CVE-2017-7615: Mantisbt

High severity, CVSS 8.8. EPSS: 91.1% chance of exploitation in the next 30 days.

MantisBT through 2.3.0 allows arbitrary password reset and unauthenticated admin access via an empty confirm_hash value to verify.php.

Affected products

  • Mantisbt Mantisbt: up to and including 2.3.0

Published 2017-04-16. Last modified 2026-06-17.