PT-2026-39873 · Mantisbt · Mantisbt
Published
2026-05-11
·
Updated
2026-05-19
·
CVE-2026-33052
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Mantis Bug Tracker (MantisBT) versions 2.28.0 through 2.28.1
Description
A low-privileged authenticated user with the
add profile threshold permission can create a global profile even without the manage global profile threshold permission. This is achieved by tampering with the user id parameter during a valid profile creation request, leading to privilege escalation.Recommendations
Update to version 2.28.2.
Exploit
Fix
LPE
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mantisbt