CVE-2024-45792

Severity CVSS v4.0:
MEDIUM
Type:
CWE-200 Information Leak / Disclosure
Publication date:
30/09/2024
Last modified:
15/08/2025

Description

Mantis Bug Tracker (MantisBT) is an open source issue tracker. Using a crafted POST request, an unprivileged, registered user is able to retrieve information about other users' personal system profiles. This vulnerability is fixed in 2.26.4.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mantisbt:mantisbt:*:*:*:*:*:*:*:* 2.26.4 (excluding)