Description

Mantis Bug Tracker (MantisBT) is an open source issue tracker. In versions 2.27.1 and below, when a user edits their profile to change their e-mail address, the system saves it without validating that it actually belongs to the user. This could result in storing an invalid email address, preventing the user from receiving system notifications. Notifications sent to another person's email address could lead to information disclosure. This issue is fixed in version 2.27.2.

INFO

Published Date :

2025-11-04T20:48:03.428Z

Last Modified :

2025-11-04T21:03:12.088Z

Source :

GitHub_M
AFFECTED PRODUCTS

The following products are affected by CVE-2025-55155 vulnerability.

Vendors Products
Mantisbt
  • Mantisbt

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact