CVE-2014-6316: Mantisbt

Medium severity, CVSS 5.8. EPSS: 2.3% chance of exploitation in the next 30 days.

core/string_api.php in MantisBT before 1.2.18 does not properly categorize URLs when running under the web root, which allows remote attackers to conduct open redirect and phishing attacks via a crafted URL in the return parameter to login_page.php.

Affected products

  • Mantisbt Mantisbt: up to and including 1.2.17

Published 2014-12-12. Last modified 2026-06-17.