An issue was discovered in MantisBT before 2.24.5. It...
High severity
Unreviewed
Published
Apr 21, 2022
to the GitHub Advisory Database
•
Updated Jan 27, 2023
Description
Published by the National Vulnerability Database
Mar 7, 2021
Published to the GitHub Advisory Database
Apr 21, 2022
Last updated
Jan 27, 2023
An issue was discovered in MantisBT before 2.24.5. It associates a unique cookie string with each user. This string is not reset upon logout (i.e., the user session is still considered valid and active), allowing an attacker who somehow gained access to a user's cookie to login as them.
References