← Back

CVE-2008-4689

nvd nist
Published: Oct 22, 2008Modified: Apr 23, 2026

JSON object

Loading...
7.5
Vector
AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploitability: 10.0 / Impact: 6.4
Source: NVD

Description

Mantis before 1.1.3 does not unset the session cookie during logout, which makes it easier for remote attackers to hijack sessions.

Affected (12)

Products: Mantis: Mantis
1 product
Mantis
Configuration A
12 vulnerable
Vulnerable SoftwareAffected Versions
Mantis
Up to 1.1.2
Version 0.19.3
Version 0.19.4
Version 1.0.1
Version 1.0.2
Version 1.0.3
Version 1.0.4
Version 1.0.5
Version 1.0.6
Version 1.0.7
Version 1.0.8
Version 1.1.1

Timeline

No history available yet.