MantisBT Insufficient Session Expiration cookie string not reset after logout
High severity
GitHub Reviewed
Published
Apr 21, 2022
to the GitHub Advisory Database
•
Updated Jun 9, 2025
Description
Published by the National Vulnerability Database
Mar 7, 2021
Published to the GitHub Advisory Database
Apr 21, 2022
Reviewed
May 28, 2025
Last updated
Jun 9, 2025
An issue was discovered in MantisBT before 2.24.5. It associates a unique cookie string with each user. This string is not reset upon logout (i.e., the user session is still considered valid and active), allowing an attacker who somehow gained access to a user's cookie to login as them.
References