High severityNVD Advisory· Published Mar 7, 2021· Updated Aug 7, 2024
CVE-2009-20001
CVE-2009-20001
Description
An issue was discovered in MantisBT before 2.24.5. It associates a unique cookie string with each user. This string is not reset upon logout (i.e., the user session is still considered valid and active), allowing an attacker who somehow gained access to a user's cookie to login as them.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
mantisbt/mantisbtPackagist | < 2.24.5 | 2.24.5 |
Affected products
2- MantisBT/MantisBTdescription
Patches
Vulnerability mechanics
References
5- github.com/advisories/GHSA-jm72-67rm-763jghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2009-20001ghsaADVISORY
- github.com/mantisbt/mantisbt/commit/79a78c09d5ef5ce098adc73f6f1416f00fc238a5ghsaWEB
- mantisbt.org/bugs/view.phpghsax_refsource_MISCWEB
- mantisbt.org/bugs/view.phpghsax_refsource_MISCWEB
News mentions
0No linked articles in our index yet.