CVE-2008-4689

Mantis < 1.1.2 - Authentication Bypass

Title source: rule

Description

Mantis before 1.1.3 does not unset the session cookie during logout, which makes it easier for remote attackers to hijack sessions.

Scores

EPSS 0.0111
EPSS Percentile 77.9%

Classification

CWE
CWE-287
Status draft

Affected Products (12)

mantis/mantis < 1.1.2
mantis/mantis
mantis/mantis
mantis/mantis
mantis/mantis
mantis/mantis
mantis/mantis
mantis/mantis
mantis/mantis
mantis/mantis
mantis/mantis
mantis/mantis

Timeline

Published Oct 22, 2008
Tracked Since Feb 18, 2026