CVE-2024-23830

CVSS V2 None CVSS V3 None
Description
MantisBT is an open source issue tracker. Prior to version 2.26.1, an unauthenticated attacker who knows a user's email address and username can hijack the user's account by poisoning the link in the password reset notification message. A patch is available in version 2.26.1. As a workaround, define `$g_path` as appropriate in `config_inc.php`.
Overview
  • CVE ID
  • CVE-2024-23830
  • Assigner
  • GitHub_M
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-02-20T21:44:27.707Z
  • Last Modified Date
  • 2024-02-20T21:44:27.707Z
History
Created Old Value New Value Data Type Notes
2024-06-26 06:52:53 Added to TrackCVE