MantisBT lacks verification when changing a user's email address
Description
Published to the GitHub Advisory Database
Nov 3, 2025
Reviewed
Nov 3, 2025
Published by the National Vulnerability Database
Nov 4, 2025
Last updated
Nov 4, 2025
When a user edits their profile to change their e-mail address, the system saves it without validating that it actually belongs to the user.
Impact
This could result in storing an invalid email address, preventing the user from receiving system notifications.
Notifications sent to another person's email address could lead to information disclosure.
Patches
Fixed in 2.27.2.
Workarounds
None
Credits
Thanks to @ncrcs for discovering and reporting the issue.
References