Session Hijacking Vulnerabilities in Mantis Bug Tracker by MantisBT
CVE-2008-4689

Currently unrated

Key Information:

Vendor

Mantis

Status
Vendor
CVE Published:
22 October 2008

What is CVE-2008-4689?

The Mantis Bug Tracker versions prior to 1.1.3 do not properly invalidate session cookies upon user logout. This oversight makes it possible for remote attackers to hijack active sessions, potentially gaining unauthorized access to sensitive information. Users are urged to upgrade to a secure version to mitigate the risk of session hijacking and maintain the integrity of their user accounts.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.