Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r3jf-hm7q-qfw5

Опубликовано: 03 нояб. 2025
Источник: github
Github: Прошло ревью
CVSS3: 6.5

Описание

MantisBT Vulnerable to Denial-of-Service (DoS) via Excessive Note Length

A lack of server-side validation for note length in MantisBT allows attackers to permanently corrupt issue activity logs by submitting extremely long notes (tested with 4,788,761 characters). Once such a note is added:

Impact

  • The entire activity stream becomes unviewable (UI fails to render).
  • New notes cannot be displayed, effectively breaking all future collaboration on the issue.

Patches

Fixed in 2.27.2.

Workarounds

None

Credits

Thanks to Mazen Mahmoud (@TheAmazeng) for reporting the vulnerability.

Пакеты

Наименование

mantisbt/mantisbt

composer
Затронутые версииВерсия исправления

< 2.27.2

2.27.2

EPSS

Процентиль: 18%
0.00058
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-770

Связанные уязвимости

CVSS3: 6.5
nvd
3 месяца назад

Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.27.1 and below allow attackers to permanently corrupt issue activity logs by submitting extremely long notes (tested with 4,788,761 characters) due to a lack of server-side validation of note length. Once such a note is added, the activity stream UI fails to render; therefore, new notes cannot be displayed, effectively breaking all future collaboration on the issue. This issue is fixed in version 2.27.2.

CVSS3: 6.5
debian
3 месяца назад

Mantis Bug Tracker (MantisBT) is an open source issue tracker. Version ...

EPSS

Процентиль: 18%
0.00058
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-770