CVE-2014-6316

medium

Description

core/string_api.php in MantisBT before 1.2.18 does not properly categorize URLs when running under the web root, which allows remote attackers to conduct open redirect and phishing attacks via a crafted URL in the return parameter to login_page.php.

References

https://www.mantisbt.org/bugs/view.php?id=17648

https://github.com/mantisbt/mantisbt/commit/e66ecc9f

https://exchange.xforce.ibmcloud.com/vulnerabilities/99128

http://www.openwall.com/lists/oss-security/2014/12/03/11

http://www.debian.org/security/2015/dsa-3120

http://secunia.com/advisories/62101

Details

Source: Mitre, NVD

Published: 2014-12-12

Updated: 2017-09-08

Risk Information

CVSS v2

Base Score: 5.8

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:N

Severity: Medium

CVSS v3

Base Score: 6.1

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Severity: Medium