Improper Authentication The advisory has been revoked - it doesn't affect any version of package mantisbt/mantisbt  (opens in a new tab)


Threat Intelligence

EPSS
0.08% (37th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Improper Authentication vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-PHP-MANTISBTMANTISBT-1083226
  • published8 Mar 2021
  • disclosed8 Mar 2021
  • creditUnknown

Introduced: 8 Mar 2021

CVE-2009-20001  (opens in a new tab)
CWE-287  (opens in a new tab)

Amendment

This was deemed not a vulnerability.

Overview

mantisbt/mantisbt is a mantis bug tracker.

Affected versions of this package are vulnerable to Improper Authentication. It associates a unique cookie string with each user. This string is not reset upon logout (i.e., the user session is still considered valid and active), allowing an attacker who somehow gained access to a user's cookie to login as them.