Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2009-20001 Details

Description

An issue was discovered in MantisBT before 2.24.5. It associates a unique cookie string with each user. This string is not reset upon logout (i.e., the user session is still considered valid and active), allowing an attacker who somehow gained access to a user's cookie to login as them.

Metrics

CVSS 3.x Severity and Vector Strings:

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

URLSource(s)Tag(s)
https://mantisbt.org/bugs/view.php?id=11296 CVEIssue TrackingVendor Advisory
https://mantisbt.org/bugs/view.php?id=27976 CVEExploitIssue TrackingVendor Advisory
https://mantisbt.org/bugs/view.php?id=11296 [email protected]Issue TrackingVendor Advisory
https://mantisbt.org/bugs/view.php?id=27976 [email protected]ExploitIssue TrackingVendor Advisory

Weakness Enumeration

CWE-IDCWE NameSource
CWE-613Insufficient Session Expiration[email protected]

Affected Products

ProductVersions
mantisbt mantisbt
< 2.24.5

CPE

  • cpe:2.3:a:mantisbt:mantisbt:*:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.

Change History

4 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2009-20001
NVD Published Date:
Mar 7, 2021
NVD Last Modified:
Jun 16, 2026
Source:
[email protected]
CVE-2009-20001 Details - Not Deferred