|
|||
Rule General Information |
---|
Release Date: | 2017-07-07 | |
Rule Name: | Mantis Bug Tracker Verify.php Confirm_hash Remote Password Reset Vulnerability -1 (CVE-2017-7615) | |
Severity: | ||
CVE ID: | ||
Rule Protection Details |
---|
Description: | MantisBT through 2.3.0 allows arbitrary password reset and unauthenticated admin access via an empty confirm_hash value to verify.php. | |
Impact: | An attacker can take advantage of the vulnerability to bypass the security policy implemented by the software administrator, and perform unauthorized actions to the target system. | |
Affected OS: | Windows, Other Unix, FreeBSD, Linux | |
Reference: | SecurityFocusBID:97707 ExploitDB:41890 http://hyp3rlinx.altervista.org/advisories/MANTIS-BUG-TRACKER-PRE-AUTH-REMOTE-PASSWORD-RESET.txt http://www.openwall.com/lists/oss-security/2017/04/16/2 |
|
Solutions |
---|
More advisories have been published on the website, please visit for more suggestions: https://www.mantisbt.org/blog/?p=518 |