There are some nearly ten year old discussions on user password encryption/salting on
Mantis' own bugtracker. I have no admin experience with software security and thus
probably shouldn't say something at all - but at least it looks as if they implemented
some useful measures already a while ago.
Of course, everyone is nonetheless encouraged to change their passwords, especially if
these are no unique Mantis passwords.
- Carsten