Mantis Bug Tracker(MantisBT)是Mantis Bug Tracker开源的一个 bug 跟踪器。 Mantis Bug Tracker 2.28.1及之前版本存在信息泄露漏洞,该漏洞源于允许用户列出并下载自己上传到由其他用户创建的问题的附件,即使该问题变为私有后仍可访问,可能导致读取访问撤销绕过。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-34754 | 4.3 MEDIUM | MantisBT allows unauthorized users to upload attachments to restricted issues via REST API |
| CVE-2026-33052 | MantisBT: Authorization Bypass in Global Profile Creation | |
| CVE-2026-34463 | MantisBT has Stored HTML Injection/XSS via Clone Issue Form | |
| CVE-2026-34579 | MantisBT has an authorization bypass via private issue monitoring | |
| CVE-2026-34390 | MantisBT: Privilege Escalation from Manager to Administrator | |
| CVE-2026-34970 | MantisBT Bugnote Revision Page Leaks Private Issue Metadata After Issue Access Is Revoked |
No comments yet