CVE-2014-6316: Mantisbt
Medium severity, CVSS 5.8. EPSS: 2.3% chance of exploitation in the next 30 days.
core/string_api.php in MantisBT before 1.2.18 does not properly categorize URLs when running under the web root, which allows remote attackers to conduct open redirect and phishing attacks via a crafted URL in the return parameter to login_page.php.
Affected products
- Mantisbt Mantisbt: up to and including 1.2.17
Published 2014-12-12. Last modified 2026-06-17.