Описание
MantisBT is an open source issue tracker. Prior to version 2.26.1, an unauthenticated attacker who knows a user's email address and username can hijack the user's account by poisoning the link in the password reset notification message. A patch is available in version 2.26.1. As a workaround, define $g_path as appropriate in config_inc.php.
Ссылки
- Patch
- PatchVendor Advisory
- ExploitVendor Advisory
- Patch
- PatchVendor Advisory
- ExploitVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2.26.1 (исключая)
cpe:2.3:a:mantisbt:mantisbt:*:*:*:*:*:*:*:*
EPSS
Процентиль: 80%
0.0133
Низкий
8.3 High
CVSS3
Дефекты
CWE-74
NVD-CWE-noinfo
Связанные уязвимости
CVSS3: 8.3
debian
почти 2 года назад
MantisBT is an open source issue tracker. Prior to version 2.26.1, an ...
EPSS
Процентиль: 80%
0.0133
Низкий
8.3 High
CVSS3
Дефекты
CWE-74
NVD-CWE-noinfo