Two vulnerabilities in MantisBT



Published: 2017-05-23
Risk Medium
Patch available YES
Number of vulnerabilities 2
CVE-ID CVE-2017-7620
CWE-ID CWE-352
CWE-601
Exploitation vector Network
Public exploit Public exploit code for vulnerability #1 is available.
Public exploit code for vulnerability #2 is available.
Vulnerable software
Subscribe
MantisBT
Web applications / Other software

Vendor mantisbt.sourceforge.net

Security Bulletin

This security bulletin contains information about 2 vulnerabilities.

1) Cross-site request forgery

EUVDB-ID: #VU6631

Risk: Medium

CVSSv3.1: 6.4 [CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L/E:P/RL:O/RC:C]

CVE-ID: CVE-2017-7620

CWE-ID: CWE-352 - Cross-Site Request Forgery (CSRF)

Exploit availability: Yes

Description

The vulnerability allows a remote attacker to perform CSRF attacks.

The vulnerability exists due to improper validation of the HTTP request origin in 'string_api.php'. A remote attacker can create a specially specially crafted web page, trick the authenticated victim into visiting it and inject arbitrary permalinks into the mantisbt Web Interface.

Successful exploitation of the vulnerability may result in cross-site request forgery conducting.

Mitigation

Update to version 1.3.11, 2.3.3, 2.4.1.

Vulnerable software versions

MantisBT: 1.0.0 - 2.4.0

External links

http://hyp3rlinx.altervista.org/advisories/MANTIS-BUG-TRACKER-CSRF-PERMALINK-INJECTION.txt


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability. However, proof of concept for this vulnerability is available.

2) Open redirect

EUVDB-ID: #VU6633

Risk: Low

CVSSv3.1: 4.2 [CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N/E:P/RL:O/RC:C]

CVE-ID: N/A

CWE-ID: CWE-601 - URL Redirection to Untrusted Site ('Open Redirect')

Exploit availability: No

Description

The vulnerability allows a remote attacker to redirect website visitors to external websites.

The weakness exists in 'return' parameter in 'login_page.php' due to incorrect validation of redirected URL. A remote attacker can create a specially crafted link, redirect the victim on external website page.

Successful exploitation of the vulnerability may result in conducting further attacks.

Mitigation

Update to version 1.3.11, 2.3.3, 2.4.1.

Vulnerable software versions

MantisBT: 1.0.0 - 2.4.0

External links

http://hyp3rlinx.altervista.org/advisories/MANTIS-BUG-TRACKER-CSRF-PERMALINK-INJECTION.txt


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability. However, proof of concept for this vulnerability is available.



###SIDEBAR###