CVE-2025-62520: Mantisbt

Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.

Mantis Bug Tracker (MantisBT) is an open source issue tracker. In versions 2.27.1 and below, due to insufficient access-level checks, any non-admin user with access to manage_config_columns_page.php can use the Copy From action to retrieve the columns configuration from a private project they have no access to. This issue is fixed in version 2.27.2.

Affected products

  • Mantisbt Mantisbt: before 2.27.2 (fixed in 2.27.2)

Published 2025-11-04. Last modified 2026-06-17.