Описание
MantisBT through 2.3.0 allows arbitrary password reset and unauthenticated admin access via an empty confirm_hash value to verify.php.
Пакеты
Пакет | Статус | Версия исправления | Релиз | Тип |
---|---|---|---|---|
mantis | removed | package | ||
mantis | end-of-life | wheezy | package |
Примечания
https://www.openwall.com/lists/oss-security/2017/04/16/2
EPSS
Процентиль: 100%
0.9264
Критический
Связанные уязвимости
CVSS3: 8.8
ubuntu
больше 8 лет назад
MantisBT through 2.3.0 allows arbitrary password reset and unauthenticated admin access via an empty confirm_hash value to verify.php.
CVSS3: 8.8
nvd
больше 8 лет назад
MantisBT through 2.3.0 allows arbitrary password reset and unauthenticated admin access via an empty confirm_hash value to verify.php.
EPSS
Процентиль: 100%
0.9264
Критический