MantisBT through 2.3.0 allows arbitrary password reset and unauthenticated admin access via an empty confirm_hash value to verify.php.
The product contains a mechanism for users to recover or change their passwords without knowing the original password, but the mechanism is weak.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/97707 | vdb entry third party advisory broken link |
https://mantisbt.org/bugs/view.php?id=22690 | issue tracking patch vendor advisory |
http://www.openwall.com/lists/oss-security/2017/04/16/2 | third party advisory mailing list |
https://www.exploit-db.com/exploits/41890/ | exploit vdb entry third party advisory |
http://hyp3rlinx.altervista.org/advisories/MANTIS-BUG-TRACKER-PRE-AUTH-REMOTE-PASSWORD-RESET.txt | third party advisory exploit |
http://packetstormsecurity.com/files/159219/Mantis-Bug-Tracker-2.3.0-Remote-Code-Execution.html | exploit vdb entry third party advisory |