6.5
CVSSv2

CVE-2017-7615

Published: 16/04/2017 Updated: 20/01/2023
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 655
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

MantisBT up to and including 2.3.0 allows arbitrary password reset and unauthenticated admin access via an empty confirm_hash value to verify.php.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mantisbt mantisbt

Exploits

[+] Credits: John Page aka hyp3rlinx [+] Website: hyp3rlinxaltervistaorg [+] Source: hyp3rlinxaltervistaorg/advisories/MANTIS-BUG-TRACKER-PRE-AUTH-REMOTE-PASSWORD-RESETtxt [+] ISR: ApparitionSec Vendor: ================ wwwmantisbtorg Product: ================== Mantis Bug Tracker v130 / 230 MantisBT is a p ...
Mantis Bug Tracker version 230 suffers from a remote code execution vulnerability ...
Mantis Bug Tracker versions 130 and 230 suffer from a pre-authentication remote password reset vulnerability ...