CVE-2017-7620
Last modified
CVE-2017-7620 is a vulnerability of currently unknown severity. MantisBT before 1.3.11, 2.x before 2.3.3, and 2.4.x before 2.4.1 omits a backslash check in string_api.php and consequently has conflicting interpretations of an initial \/ substring as introducing either a local pathname or a remote hostname, which leads to (1) arbitrary Permalink Injection via CSRF attacks on a permalink_page.php?url= URI and (2) an open redirect via a login_page.php?return= URI.. EPSS estimates a 1.36% chance of exploitation in the next 30 days.
Description
MantisBT before 1.3.11, 2.x before 2.3.3, and 2.4.x before 2.4.1 omits a backslash check in string_api.php and consequently has conflicting interpretations of an initial \/ substring as introducing either a local pathname or a remote hostname, which leads to (1) arbitrary Permalink Injection via CSRF attacks on a permalink_page.php?url= URI and (2) an open redirect via a login_page.php?return= URI.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mantisbt | Mantisbt | <= 1.3.10 |
| Mantisbt | Mantisbt | 2.0.0 |
| Mantisbt | Mantisbt | 2.0.1 |
| Mantisbt | Mantisbt | 2.1.0 |
| Mantisbt | Mantisbt | 2.1.1 |
| Mantisbt | Mantisbt | 2.1.2 |
| Mantisbt | Mantisbt | 2.2.0 |
| Mantisbt | Mantisbt | 2.2.2 |
| Mantisbt | Mantisbt | 2.2.3 |
| Mantisbt | Mantisbt | 2.2.4 |
| Mantisbt | Mantisbt | 2.4.0 |
References
- http://hyp3rlinx.altervista.org/advisories/MANTIS-BUG-TRACKER-CSRF-PERMALINK-INJECTION.txtExploit, Third Party Advisory
- https://mantisbt.org/bugs/view.php?id=22702Issue Tracking
- https://mantisbt.org/bugs/view.php?id=22816Issue Tracking
- https://www.exploit-db.com/exploits/42043/Exploit, Third Party Advisory
- http://hyp3rlinx.altervista.org/advisories/MANTIS-BUG-TRACKER-CSRF-PERMALINK-INJECTION.txtExploit, Third Party Advisory
- https://mantisbt.org/bugs/view.php?id=22702Issue Tracking
- https://mantisbt.org/bugs/view.php?id=22816Issue Tracking
- https://www.exploit-db.com/exploits/42043/Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-7620?
How severe is CVE-2017-7620?
How do I fix CVE-2017-7620?
Are you affected by CVE-2017-7620?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
