Mantisbt

Mantisbt

119 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.03%
  • Veröffentlicht 04.11.2025 21:31:13
  • Zuletzt bearbeitet 10.11.2025 17:55:42

Mantis Bug Tracker (MantisBT) is an open source issue tracker. In versions 2.27.1 and below, due to insufficient access-level checks, any non-admin user with access to manage_config_columns_page.php can use the Copy From action to retrieve the column...

Exploit
  • EPSS 0.02%
  • Veröffentlicht 04.11.2025 20:48:03
  • Zuletzt bearbeitet 10.11.2025 18:02:32

Mantis Bug Tracker (MantisBT) is an open source issue tracker. In versions 2.27.1 and below, when a user edits their profile to change their e-mail address, the system saves it without validating that it actually belongs to the user. This could resul...

  • EPSS 0.08%
  • Veröffentlicht 04.11.2025 20:31:01
  • Zuletzt bearbeitet 10.11.2025 17:59:50

Mantis Bug Tracker (MantisBT) is an open source issue tracker. Due to incorrect use of loose (==) instead of strict (===) comparison in the authentication code in versions 2.27.1 and below.PHP type juggling will cause certain MD5 hashes matching scie...

  • EPSS 0.05%
  • Veröffentlicht 04.11.2025 00:20:28
  • Zuletzt bearbeitet 07.11.2025 18:30:03

Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.27.1 and below allow attackers to permanently corrupt issue activity logs by submitting extremely long notes (tested with 4,788,761 characters) due to a lack of server-side val...

  • EPSS 0.38%
  • Veröffentlicht 30.09.2024 15:15:05
  • Zuletzt bearbeitet 15.08.2025 14:09:44

Mantis Bug Tracker (MantisBT) is an open source issue tracker. Using a crafted POST request, an unprivileged, registered user is able to retrieve information about other users' personal system profiles. This vulnerability is fixed in 2.26.4.

  • EPSS 0.23%
  • Veröffentlicht 14.05.2024 15:38:30
  • Zuletzt bearbeitet 16.01.2025 16:42:57

MantisBT (Mantis Bug Tracker) is an open source issue tracker. Improper escaping of a custom field's name allows an attacker to inject HTML and, if CSP settings permit, achieve execution of arbitrary JavaScript when resolving or closing issues (`bug...

  • EPSS 0.29%
  • Veröffentlicht 14.05.2024 15:38:29
  • Zuletzt bearbeitet 16.01.2025 16:44:40

MantisBT (Mantis Bug Tracker) is an open source issue tracker. If an issue references a note that belongs to another issue that the user doesn't have access to, then it gets hyperlinked. Clicking on the link gives an access denied error as expected, ...

Exploit
  • EPSS 0.23%
  • Veröffentlicht 14.05.2024 15:38:28
  • Zuletzt bearbeitet 16.01.2025 16:40:04

MantisBT (Mantis Bug Tracker) is an open source issue tracker. Insufficient access control in the registration and password reset process allows an attacker to reset another user's password and takeover their account, if the victim has an incomplete ...

Exploit
  • EPSS 1.33%
  • Veröffentlicht 20.02.2024 22:15:08
  • Zuletzt bearbeitet 18.12.2024 18:03:25

MantisBT is an open source issue tracker. Prior to version 2.26.1, an unauthenticated attacker who knows a user's email address and username can hijack the user's account by poisoning the link in the password reset notification message. A patch is av...

  • EPSS 0.37%
  • Veröffentlicht 16.10.2023 22:15:12
  • Zuletzt bearbeitet 11.08.2025 15:15:27

MantisBT is an open source bug tracker. Due to insufficient access-level checks on the Wiki redirection page, any user can reveal private Projects' names, by accessing wiki.php with sequentially incremented IDs. This issue has been addressed in commi...