CVE-2017-7620
medium
CVSS v3
6.5
VIR risk
6.5
Description
MantisBT vulnerable to CSRF and Open Redirect attacks
Predictions
Exploit likelihood
75%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No vendor mitigations ingested yet for this CVE. The mitigation-content worker queues fetches as references arrive — check back in a few minutes, or see the references list below.
Package impact
| Ecosystem | Package | Vulnerable | Fixed |
|---|---|---|---|
| Packagist | mantisbt/mantisbt | <1.3.11 | 1.3.11 |
| Packagist | mantisbt/mantisbt | >=2.0.0,<2.3.3 | 2.3.3 |
| Packagist | mantisbt/mantisbt | >=2.4.0,<2.4.1 | 2.4.1 |
Application impact
References
- http://hyp3rlinx.altervista.org/advisories/MANTIS-BUG-TRACKER-CSRF-PERMALINK-INJECTION.txt
- http://www.securitytracker.com/id/1038538
- https://mantisbt.org/bugs/view.php?id=22702
- https://mantisbt.org/bugs/view.php?id=22816
- https://www.exploit-db.com/exploits/42043/
- https://nvd.nist.gov/vuln/detail/CVE-2017-7620
- https://github.com/mantisbt/mantisbt/commit/2d2309a384bcd9d4b6d7d2928e8ded2c46d2d7b0
- https://github.com/mantisbt/mantisbt/commit/8b6787c8d321ee0ced5fb74ac3f34b67b4b7b26c
- https://github.com/mantisbt/mantisbt/commit/c4f50e5df6b189abb1d717a5f7dbab5cbfef8165
- https://github.com/mantisbt/mantisbt
- https://www.exploit-db.com/exploits/42043
CWEs
CWE-352
💬 Discuss CVE-2017-7620 on VIR Community →
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.