CVE Vulnerabilities

CVE-2015-1042

Published: Feb 10, 2015 | Modified: Jan 12, 2021
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

The string_sanitize_url function in core/string_api.php in MantisBT 1.2.0a3 through 1.2.18 uses an incorrect regular expression, which allows remote attackers to conduct open redirect and phishing attacks via a URL with a :/ (colon slash) separator in the return parameter to login_page.php, a different vulnerability than CVE-2014-6316.

Affected Software

Name Vendor Start Version End Version
Mantisbt Mantisbt 1.2.0-alpha3 (including) 1.2.0-alpha3 (including)
Mantisbt Mantisbt 1.2.0-rc1 (including) 1.2.0-rc1 (including)
Mantisbt Mantisbt 1.2.0-rc2 (including) 1.2.0-rc2 (including)
Mantisbt Mantisbt 1.2.1 (including) 1.2.1 (including)
Mantisbt Mantisbt 1.2.2 (including) 1.2.2 (including)
Mantisbt Mantisbt 1.2.3 (including) 1.2.3 (including)
Mantisbt Mantisbt 1.2.4 (including) 1.2.4 (including)
Mantisbt Mantisbt 1.2.5 (including) 1.2.5 (including)
Mantisbt Mantisbt 1.2.6 (including) 1.2.6 (including)
Mantisbt Mantisbt 1.2.7 (including) 1.2.7 (including)
Mantisbt Mantisbt 1.2.8 (including) 1.2.8 (including)
Mantisbt Mantisbt 1.2.9 (including) 1.2.9 (including)
Mantisbt Mantisbt 1.2.10 (including) 1.2.10 (including)
Mantisbt Mantisbt 1.2.11 (including) 1.2.11 (including)
Mantisbt Mantisbt 1.2.12 (including) 1.2.12 (including)
Mantisbt Mantisbt 1.2.13 (including) 1.2.13 (including)
Mantisbt Mantisbt 1.2.14 (including) 1.2.14 (including)
Mantisbt Mantisbt 1.2.15 (including) 1.2.15 (including)
Mantisbt Mantisbt 1.2.16 (including) 1.2.16 (including)
Mantisbt Mantisbt 1.2.17 (including) 1.2.17 (including)
Mantisbt Mantisbt 1.2.18 (including) 1.2.18 (including)
Mantis Ubuntu lucid *
Mantis Ubuntu precise *

References