← Back

CVE-2015-1042

nvd nist
Published: Feb 10, 2015Modified: May 6, 2026

JSON object

Loading...
5.8
Vector
AV:N/AC:M/Au:N/C:P/I:P/A:N
Exploitability: 8.6 / Impact: 4.9
Source: NVD

Description

The string_sanitize_url function in core/string_api.php in MantisBT 1.2.0a3 through 1.2.18 uses an incorrect regular expression, which allows remote attackers to conduct open redirect and phishing attacks via a URL with a ":/" (colon slash) separator in the return parameter to login_page.php, a different vulnerability than CVE-2014-6316.

Affected (21)

Products: Mantisbt: Mantisbt
1 product
Mantisbt
Configuration A
21 vulnerable
Vulnerable SoftwareAffected Versions
Mantisbt
Version 1.2.0 alpha3
Version 1.2.0 rc1
Version 1.2.0 rc2
Version 1.2.10
Version 1.2.11
Version 1.2.12
Version 1.2.13
Version 1.2.14
Version 1.2.15
Version 1.2.16
Version 1.2.17
Version 1.2.18
Version 1.2.1
Version 1.2.2
Version 1.2.3
Version 1.2.4
Version 1.2.5
Version 1.2.6
Version 1.2.7
Version 1.2.8
Version 1.2.9

Timeline

No history available yet.