CVE 5.4 MEDIUM

MantisBT: Authentication bypass for some passwords due to PHP type juggling_CVE-2025-55155

5.4 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

Description

Mantis Bug Tracker (MantisBT) is an open source issue tracker. In versions 2.27.1 and below, when a user edits their profile to change their e-mail address, the system saves it without validating that it actually belongs to the user. This could result in storing an invalid email address, preventing the user from receiving system notifications. Notifications sent to another person's email address could lead to information disclosure. This issue is fixed in version 2.27.2.

Basic Information

ID CVE-2025-55155
Source GitHub_M
Published Nov 4, 2025 at 20:48
Modified Nov 4, 2025 at 21:03

Affected Product

Vendor mantisbt
Product mantisbt
Version < 2.27.2
Affected Versions mantisbt mantisbt < 2.27.2

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.