CVE-2024-45792

Mantis Bug Tracker (MantisBT) is an open source issue tracker. Using a crafted POST request, an unprivileged, registered user is able to retrieve information about other users' personal system profiles. This vulnerability is fixed in 2.26.4.
Configurations

Configuration 1 (hide)

cpe:2.3:a:mantisbt:mantisbt:*:*:*:*:*:*:*:*

History

15 Aug 2025, 14:09

Type Values Removed Values Added
First Time Mantisbt mantisbt
Mantisbt
CWE NVD-CWE-noinfo
CPE cpe:2.3:a:mantisbt:mantisbt:*:*:*:*:*:*:*:*
References () https://github.com/mantisbt/mantisbt/commit/ef0f820284032350cc20a39ff9cb2010d5463b41 - () https://github.com/mantisbt/mantisbt/commit/ef0f820284032350cc20a39ff9cb2010d5463b41 - Patch
References () https://github.com/mantisbt/mantisbt/security/advisories/GHSA-h5q3-fjp4-2x7r - () https://github.com/mantisbt/mantisbt/security/advisories/GHSA-h5q3-fjp4-2x7r - Patch, Vendor Advisory
References () https://mantisbt.org/bugs/view.php?id=34640 - () https://mantisbt.org/bugs/view.php?id=34640 - Issue Tracking
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5

04 Oct 2024, 13:51

Type Values Removed Values Added
Summary
  • (es) Mantis Bug Tracker (MantisBT) es un rastreador de errores de código abierto. Mediante una solicitud POST manipulada, un usuario registrado sin privilegios puede recuperar información sobre los perfiles personales del sistema de otros usuarios. Esta vulnerabilidad se solucionó en la versión 2.26.4.

30 Sep 2024, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-09-30 15:15

Updated : 2025-08-15 14:09


NVD link : CVE-2024-45792

Mitre link : CVE-2024-45792

CVE.ORG link : CVE-2024-45792


JSON object : View

Products Affected

mantisbt

  • mantisbt
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

NVD-CWE-noinfo