PT-2025-44804 · Unknown · Mantis Bug Tracker

Published

2025-11-03

·

Updated

2025-11-05

·

CVE-2025-55155

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Mantis Bug Tracker versions 2.27.1 and below
Description Mantis Bug Tracker is an open source issue tracker. When a user modifies their profile to update their email address, the system saves the change without verifying ownership. This can lead to storing an invalid email address, potentially preventing the user from receiving system notifications. Notifications being sent to an incorrect email address could result in information disclosure.
Recommendations Update to version 2.27.2 or later.

Exploit

Fix

Insufficient Verification of Data Authenticity

Weakness Enumeration

Related Identifiers

CVE-2025-55155
GHSA-Q747-C74M-69PR

Affected Products

Mantis Bug Tracker