Open redirect in MantisBT - #VU6633

 

Open redirect in MantisBT - #VU6633

Published: May 23, 2017


Vulnerability identifier: #VU6633
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-601
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to redirect website visitors to external websites.

The weakness exists in 'return' parameter in 'login_page.php' due to incorrect validation of redirected URL. A remote attacker can create a specially crafted link, redirect the victim on external website page.

Successful exploitation of the vulnerability may result in conducting further attacks.

Affected software

MantisBT

Remediation

Update to version 1.3.11, 2.3.3, 2.4.1.


External References

Related Security Bulletins