High severity8.3NVD Advisory· Published Feb 20, 2024· Updated Jun 17, 2026
CVE-2024-23830
CVE-2024-23830
Description
MantisBT is an open source issue tracker. Prior to version 2.26.1, an unauthenticated attacker who knows a user's email address and username can hijack the user's account by poisoning the link in the password reset notification message. A patch is available in version 2.26.1. As a workaround, define $g_path as appropriate in config_inc.php.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
mantisbt/mantisbtPackagist | < 2.26.1 | 2.26.1 |
Affected products
3Patches
Vulnerability mechanics
References
5- github.com/mantisbt/mantisbt/commit/7055731d09ff12b2781410a372f790172e279744nvdPatchWEB
- github.com/mantisbt/mantisbt/security/advisories/GHSA-mcqj-7p29-9528nvdPatchVendor AdvisoryWEB
- mantisbt.org/bugs/view.phpnvdExploitVendor AdvisoryWEB
- github.com/advisories/GHSA-mcqj-7p29-9528ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-23830ghsaADVISORY
News mentions
0No linked articles in our index yet.