← Vulnerability feed

Vulnerability record · CVE-2017-7615 · published 16 April 2017

CVE-2017-7615: MantisBT weak password reset allows unauthenticated admin access

Mantisbt · Mantisbt

MantisBT through 2.3.0 mishandles password reset confirmation, allowing an attacker to supply an empty confirm_hash value to verify.php. This permits arbitrary password resets and unauthenticated administrative access to the bug tracker. The flaw is a weak password recovery mechanism (CWE-640) with a CVSS 3.1 base score of 8.8.

8.8 CVSS 3.1 High EPSS 91% · top 0.2% CWE-640 · Weak password recovery
8.8CVSS 3.1 base score, v2 6.5
91%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
12References, 6 tagged exploit
17 Jun 2026Last modified by NVD

Description

MantisBT through 2.3.0 allows arbitrary password reset and unauthenticated admin access via an empty confirm_hash value to verify.php.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityUnauthenticated administrative access and arbitrary password reset on an internet-facing application, with public exploit code and very high EPSS, make this an urgent fix.

What it is

MantisBT through 2.3.0 mishandles password reset confirmation, allowing an attacker to supply an empty confirm_hash value to verify.php. This permits arbitrary password resets and unauthenticated administrative access to the bug tracker. The flaw is a weak password recovery mechanism (CWE-640) with a CVSS 3.1 base score of 8.8.

Impact

An attacker can reset arbitrary user passwords and gain administrative access to the MantisBT instance without authenticating. That yields full control over the tracker's data and configuration.

Attack surface

Reachable over the network via HTTP requests to verify.php; the CVSS vector indicates low privileges (PR:L) and no user interaction (UI:N), though the description states unauthenticated admin access is possible. No credentials are required to trigger the empty confirm_hash path.

Exploitation

Public exploit code is referenced (ExploitDB, Packet Storm, advisory), and EPSS is very high at 0.90856 (99.8th percentile), indicating likely exploitation activity. It is not listed in CISA KEV.

What to do

  • Upgrade MantisBT to a version after 2.3.0 that fixes the verify.php confirm_hash handling.
  • If immediate upgrade is not possible, restrict network access to the MantisBT instance to trusted users only.
  • Audit and rotate administrative and user credentials on any instance that may have been exposed.
  • Review logs for password reset and verify.php requests with empty or malformed confirm_hash parameters.

Detection

  • Search web server logs for requests to verify.php with an empty or missing confirm_hash parameter.
  • Monitor for password reset activity followed by administrative logins from unusual source IPs.
  • Alert on unexpected changes to MantisBT user accounts, roles, or configuration.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-7615 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.6CVE-2019-15074Mantisbt cross-site scripting vulnerabilityThe Timeline feature in my_view_page.php in MantisBT through 2.21.1 has a stored cross-site scripting (XSS) vulnerability, allowing execution of arbi…EPSS 2.1%9.3CVE-2026-30849Mantisbt vulnerabilityMantis Bug Tracker (MantisBT) is an open source issue tracker. Versions prior to 2.28.1 running on MySQL family databases are affected by an authenti…EPSS 2.4%8.8CVE-2025-47776Mantisbt vulnerabilityMantis Bug Tracker (MantisBT) is an open source issue tracker. Due to incorrect use of loose (==) instead of strict (===) comparison in the authentic…EPSS 0.32%8.6CVE-2026-33517Mantisbt cross-site scripting vulnerabilityMantis Bug Tracker (MantisBT) is an open source issue tracker. In version 2.28.0, when deleting a Tag (tag_delete.php), improper escaping of its name…EPSS 0.35%8.6CVE-2026-33548Mantisbt cross-site scripting vulnerabilityMantis Bug Tracker (MantisBT) is an open source issue tracker. In version 2.28.0, improper escaping of tag names retrieved from History in Timeline (…EPSS 0.29%8.3CVE-2024-23830Mantisbt injection vulnerabilityMantisBT is an open source issue tracker. Prior to version 2.26.1, an unauthenticated attacker who knows a user's email address and username can hija…EPSS 0.96%8.1CVE-2009-20001Mantisbt insufficient session expiration vulnerabilityAn issue was discovered in MantisBT before 2.24.5. It associates a unique cookie string with each user. This string is not reset upon logout (i.e., t…EPSS 0.87%7.8CVE-2021-43257Mantisbt csv injection vulnerabilityLack of Neutralization of Formula Elements in the CSV API of MantisBT before 2.25.3 allows an unprivileged attacker to execute code or gain access to…EPSS 0.98%

Source: NIST National Vulnerability Database (record CVE-2017-7615), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.