216.73.217.24

CVE-2025-46556

· Published 04/11/2025 01:15 · Modified 07/11/2025 18:30

Labels: CVE-2025-46556 2025-11-04CVE-2025-46556CWE-770[email protected]

Essential information

Published
04/11/2025 01:15
Modified
07/11/2025 18:30
Author
Creator
CVSS
6.5 MEDIUM (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CVSS metrics

Description

Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.27.1 and below allow attackers to permanently corrupt issue activity logs by submitting extremely long notes (tested with 4,788,761 characters) due to a lack of server-side validation of note length. Once such a note is added, the activity stream UI fails to render; therefore, new notes cannot be displayed, effectively breaking all future collaboration on the issue. This issue is fixed in version 2.27.2.

NVD status

Status
Analyzed — CVE has had analysis completed and all data associations made.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
mantisbt / mantisbt cpe:2.3:a:mantisbt:mantisbt:*:*:*:*:*:*:*:*

References