CVE-2014-9117: Medium severity centos libreport-plugin-mantisbt vulnerability
MantisBT before 1.2.18 uses the publickey parameter value as the key to the CAPTCHA answer, which allows remote attackers to bypass the CAPTCHA protection mechanism by leveraging knowledge of a CAPTCHA answer for a publickey parameter value, as demonstrated by E4652 for the publickey value 0.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-9117?
CVE-2014-9117 is considered to have a medium severity due to its potential to allow CAPTCHA bypass.
How do I fix CVE-2014-9117?
To fix CVE-2014-9117, upgrade MantisBT to version 1.2.18 or later.
What is the impact of CVE-2014-9117?
The impact of CVE-2014-9117 is that it allows remote attackers to bypass CAPTCHA mechanisms, potentially leading to unauthorized access.
Which versions of MantisBT are affected by CVE-2014-9117?
All versions of MantisBT prior to 1.2.18 are affected by CVE-2014-9117.
Is CVE-2014-9117 easy to exploit?
Yes, CVE-2014-9117 can be easily exploited by anyone who knows the CAPTCHA answer corresponding to the public_key parameter.