CVE-2014-6316: Medium severity centos libreport-plugin-mantisbt vulnerability
Published Dec 12, 2014
·Updated
core/stringapi.php in MantisBT before 1.2.18 does not properly categorize URLs when running under the web root, which allows remote attackers to conduct open redirect and phishing attacks via a crafted URL in the return parameter to loginpage.php.
Affected Software
1 affected component
MantisBT mantisbt<=1.2.17
Event History
Dec 12, 2014
CVE Published
via MITRE·11:00 AM
Data Sourced
via MITRE·11:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-6316?
CVE-2014-6316 is considered a medium severity vulnerability due to its potential for open redirect and phishing attacks.
2
How do I fix CVE-2014-6316?
To fix CVE-2014-6316, upgrade MantisBT to version 1.2.18 or later.
3
What are the main risks associated with CVE-2014-6316?
The main risks include unauthorized access through phishing attacks and potential exploitation via crafted URLs.
4
Which versions of MantisBT are affected by CVE-2014-6316?
MantisBT versions prior to 1.2.18 are affected by CVE-2014-6316.
5
What type of attacks can CVE-2014-6316 enable?
CVE-2014-6316 can enable remote attackers to conduct open redirect and phishing attacks.