Back to Database
Status published
Medium
CVE-2024-45792
MantisBT vulnerable to information disclosure with user profiles
Vulnerability Description
Mantis Bug Tracker (MantisBT) is an open source issue tracker. Using a crafted POST request, an unprivileged, registered user is able to retrieve information about other users' personal system profiles. This vulnerability is fixed in 2.26.4.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-45792
Credits & Attribution
No credits recorded in the NVD database.
References
More from mantisbt
View All →CVE-2025-62520
MantisBT unauthorized disclosure of private project column configuration
Medium
5.3
CVE-2025-55155
MantisBT: Authentication bypass for some passwords due to PHP type juggling
Medium
5.4
CVE-2025-47776
MantisBT: Authentication bypass for some passwords due to PHP type juggling
High
8.8
CVE-2025-46556
MantisBT is Vulnerable to Denial-of-Service (DoS) attack via Excessive Note Length
Medium
6.5
CVE-2024-34081
MantisBT Cross-site Scripting vulnerability
Medium
6.6
Affected Vendor
mantisbt
View all reports →Affected Software
mantisbt
Vulnerable Versions:
< 2.26.4
Timeline
Official Publish:
September 30th, 2024
Last Modified:
September 30th, 2024
Added to House:
July 22nd, 2026