GHSA-mcqj-7p29-9528
MantisBT Host Header Injection vulnerability
Quick fix
GHSA-mcqj-7p29-9528 — mantisbt/mantisbt: upgrade to the fixed version with the command below.
composer require mantisbt/mantisbt:^2.26.1Details
### Impact Knowing a user's email address and username, an unauthenticated attacker can hijack the user's account by poisoning the link in the password reset notification message.
### Patches https://github.com/mantisbt/mantisbt/commit/7055731d09ff12b2781410a372f790172e279744
### Workarounds Define `$g_path` as appropriate in config_inc.php.
### References https://mantisbt.org/bugs/view.php?id=19381
### Credits
Thanks to the following security researchers for responsibly reporting and helping resolve this vulnerability.
- Pier-Luc Maltais (https://twitter.com/plmaltais) - Hlib Yavorskyi (https://github.com/Kerkroups) - Jingshao Chen (https://github.com/shaozi) - Brandon Roldan - nhchoudhary
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 2.26.1composer require mantisbt/mantisbt:^2.26.1References
- https://github.com/mantisbt/mantisbt/security/advisories/GHSA-mcqj-7p29-9528[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2024-23830[ADVISORY]
- https://github.com/mantisbt/mantisbt/commit/7055731d09ff12b2781410a372f790172e279744[WEB]
- https://github.com/mantisbt/mantisbt[PACKAGE]
- https://mantisbt.org/bugs/view.php?id=19381[WEB]