Due to insufficient access-level checks on the Wiki redirection page, any user can reveal private Projects' names, by accessing wiki.php with sequentially incremented IDs.
The vulnerability has been fixed in MantisBT version 2.25.8 (https://github.com/mantisbt/mantisbt/commit/65c44883f9d24f3ccef066fb523c93d8fdd7afc1).
Disable wiki integration ( $g_wiki_enable = OFF;
)
{ "github_reviewed": true, "severity": "MODERATE", "nvd_published_at": "2023-10-16T22:15:12Z", "github_reviewed_at": "2023-10-17T14:20:36Z", "cwe_ids": [ "CWE-200", "CWE-668" ] }