Mantis Bug Tracker (MantisBT) is an open source issue tracker. In versions 2.27.1 and below, when a user edits their profile to change their e-mail address, the system saves it without validating that it actually belongs to the user. This could result in storing an invalid email address, preventing the user from receiving system notifications. Notifications sent to another person's email address could lead to information disclosure. This issue is fixed in version 2.27.2.
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-q747-c74m-69pr MantisBT lacks verification when changing a user's email address
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 05 Nov 2025 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Mantisbt
Mantisbt mantisbt
Vendors & Products Mantisbt
Mantisbt mantisbt

Tue, 04 Nov 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 04 Nov 2025 21:00:00 +0000

Type Values Removed Values Added
Description Mantis Bug Tracker (MantisBT) is an open source issue tracker. In versions 2.27.1 and below, when a user edits their profile to change their e-mail address, the system saves it without validating that it actually belongs to the user. This could result in storing an invalid email address, preventing the user from receiving system notifications. Notifications sent to another person's email address could lead to information disclosure. This issue is fixed in version 2.27.2.
Title MantisBT: Authentication bypass for some passwords due to PHP type juggling
Weaknesses CWE-201
CWE-354
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-11-04T21:03:12.088Z

Reserved: 2025-08-07T18:27:23.306Z

Link: CVE-2025-55155

cve-icon Vulnrichment

Updated: 2025-11-04T21:03:07.466Z

cve-icon NVD

Status : Received

Published: 2025-11-04T21:15:39.280

Modified: 2025-11-04T21:15:39.280

Link: CVE-2025-55155

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-11-05T10:47:24Z