Mantis Bug Tracker(MantisBT)是Mantis Bug Tracker开源的一个 bug 跟踪器。 Mantis Bug Tracker 2.28.2之前版本存在安全漏洞,该漏洞源于mc_issue_update()函数允许具有update_bug_threshold权限的用户编辑其他用户的bugnotes,绕过默认的DEVELOPER阈值。以下版本受到影响:2.28.2之前版本。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-41897 | MantisBT: Reflected XSS in Rendering Dynamic Custom Textarea Field | |
| CVE-2026-42071 | MantisBT: Private Bugnote Attachment Content Leak via REST API | |
| CVE-2026-44657 | MantisBT: Stored XSS in File Download | |
| CVE-2026-44655 | MantisBT: Stored XSS on Move Attachments Admin Page |
No comments yet