CVE-2025-55155: MantisBT lacks verification when changing a user's email address
(updated )
When a user edits their profile to change their e-mail address, the system saves it without validating that it actually belongs to the user.
References
Code Behaviors & Features
Detect and mitigate CVE-2025-55155 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →