Detects MantisBT instances running on MySQL where the SOAP API's mc_login function accepts passwords as integers instead of strings. By sending the password as xsd:integer 0, MySQL's implicit type conversion causes the stored password hash to compare equal to 0, bypassing authentication entirely. An attacker who knows any username gains full API access. All versions before 2.28.1 on MySQL backends are affected.
Is your app exploitable through CVE-2026-30849?
Scan your domain free