CVE-2009-20001
An issue was discovered in MantisBT before 2.24.5. It associates a unique cookie string with each user. This string is not reset upon logout (i.e., the user session is still considered valid and active), allowing an attacker who somehow gained access to a user's cookie to login as them.
Published
2021-03-07T20:15:12.427
Last Modified
2024-11-21T01:03:53.800
Status
Modified
Source
[email protected]
Severity
CVSSv3.1: 8.1 (HIGH)
CVSSv2 Vector
AV:N/AC:L/Au:S/C:P/I:P/A:N
- Access Vector: NETWORK
- Access Complexity: LOW
- Authentication: SINGLE
- Confidentiality Impact: PARTIAL
- Integrity Impact: PARTIAL
- Availability Impact: NONE
Exploitability Score
8.0
Impact Score
4.9
Weaknesses
Affected Vendors & Products
Type |
Vendor |
Product |
Version/Range |
Vulnerable? |
Application |
mantisbt
|
mantisbt
|
< 2.24.5 |
Yes
|
References