MEDIUM · 5.8

CVE-2014-6316

core/string_api.php in MantisBT before 1.2.18 does not properly categorize URLs when running under the web root, which allows remote attackers to conduct open redirect and phishing attacks via a craft...

Vulnerability Description

core/string_api.php in MantisBT before 1.2.18 does not properly categorize URLs when running under the web root, which allows remote attackers to conduct open redirect and phishing attacks via a crafted URL in the return parameter to login_page.php.

CVSS Score

5.8

MEDIUM

AV:N/AC:M/Au:N/C:P/I:P/A:N
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
NONE

Affected Products

VendorProductVersions
MantisbtMantisbt<= 1.2.17

References

FAQ

What is CVE-2014-6316?

CVE-2014-6316 is a vulnerability with a CVSS score of 5.8 (MEDIUM). core/string_api.php in MantisBT before 1.2.18 does not properly categorize URLs when running under the web root, which allows remote attackers to conduct open redirect and phishing attacks via a craft...

How severe is CVE-2014-6316?

CVE-2014-6316 has been rated MEDIUM with a CVSS base score of 5.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2014-6316?

Check the references section above for vendor advisories and patch information. Affected products include: Mantisbt Mantisbt.