Vulnerability record · CVE-2017-7615 · published 16 April 2017
CVE-2017-7615: MantisBT weak password reset allows unauthenticated admin access
Mantisbt · Mantisbt
MantisBT through 2.3.0 mishandles password reset confirmation, allowing an attacker to supply an empty confirm_hash value to verify.php. This permits arbitrary password resets and unauthenticated administrative access to the bug tracker. The flaw is a weak password recovery mechanism (CWE-640) with a CVSS 3.1 base score of 8.8.
Description
MantisBT through 2.3.0 allows arbitrary password reset and unauthenticated admin access via an empty confirm_hash value to verify.php.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated administrative access and arbitrary password reset on an internet-facing application, with public exploit code and very high EPSS, make this an urgent fix.
What it is
MantisBT through 2.3.0 mishandles password reset confirmation, allowing an attacker to supply an empty confirm_hash value to verify.php. This permits arbitrary password resets and unauthenticated administrative access to the bug tracker. The flaw is a weak password recovery mechanism (CWE-640) with a CVSS 3.1 base score of 8.8.
Impact
An attacker can reset arbitrary user passwords and gain administrative access to the MantisBT instance without authenticating. That yields full control over the tracker's data and configuration.
Attack surface
Reachable over the network via HTTP requests to verify.php; the CVSS vector indicates low privileges (PR:L) and no user interaction (UI:N), though the description states unauthenticated admin access is possible. No credentials are required to trigger the empty confirm_hash path.
Exploitation
Public exploit code is referenced (ExploitDB, Packet Storm, advisory), and EPSS is very high at 0.90856 (99.8th percentile), indicating likely exploitation activity. It is not listed in CISA KEV.
What to do
- Upgrade MantisBT to a version after 2.3.0 that fixes the verify.php confirm_hash handling.
- If immediate upgrade is not possible, restrict network access to the MantisBT instance to trusted users only.
- Audit and rotate administrative and user credentials on any instance that may have been exposed.
- Review logs for password reset and verify.php requests with empty or malformed confirm_hash parameters.
Detection
- Search web server logs for requests to verify.php with an empty or missing confirm_hash parameter.
- Monitor for password reset activity followed by administrative logins from unusual source IPs.
- Alert on unexpected changes to MantisBT user accounts, roles, or configuration.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2017-7615 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-7615), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.