CVE-2024-45792: MantisBT vulnerable to information disclosure with user profiles
Mantis Bug Tracker (MantisBT) is an open source issue tracker. Using a crafted POST request, an unprivileged, registered user is able to retrieve information about other users' personal system profiles. This vulnerability is fixed in 2.26.4.
Other sources
Using a crafted POST request, an unprivileged, registered user is able to retrieve information about other users' personal system profiles.
Impact Disclosure of private system profiles: Platform, OS, OS version, Description.
Patches - https://github.com/mantisbt/mantisbt/commit/56bbd02dc1fb33a8de5898fd17dc3d698c847f55
Workarounds None
References https://mantisbt.org/bugs/view.php?id=34640
— GitHub
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-45792?
CVE-2024-45792 is considered a medium severity vulnerability affecting Mantis Bug Tracker.
How do I fix CVE-2024-45792?
To fix CVE-2024-45792, upgrade to MantisBT version 2.26.4 or higher.
Who is affected by CVE-2024-45792?
CVE-2024-45792 affects registered users of Mantis Bug Tracker who can send crafted POST requests.
What does CVE-2024-45792 exploit?
CVE-2024-45792 exploits a flaw that allows unprivileged users to retrieve personal system profile information of other users.
Is there a workaround for CVE-2024-45792?
There is no official workaround for CVE-2024-45792; updating to the fixed version is recommended.