{"id":"CVE-2017-7620","details":"MantisBT before 1.3.11, 2.x before 2.3.3, and 2.4.x before 2.4.1 omits a backslash check in string_api.php and consequently has conflicting interpretations of an initial \\/ substring as introducing either a local pathname or a remote hostname, which leads to (1) arbitrary Permalink Injection via CSRF attacks on a permalink_page.php?url= URI and (2) an open redirect via a login_page.php?return= URI.","aliases":["GHSA-9x76-mp7r-2xc5"],"modified":"2026-08-07T14:53:39.614330Z","published":"2017-05-21T14:29:00.180Z","references":[{"type":"WEB","url":"http://www.securitytracker.com/id/1038538"},{"type":"REPORT","url":"https://mantisbt.org/bugs/view.php?id=22702"},{"type":"REPORT","url":"https://mantisbt.org/bugs/view.php?id=22816"},{"type":"EVIDENCE","url":"http://hyp3rlinx.altervista.org/advisories/MANTIS-BUG-TRACKER-CSRF-PERMALINK-INJECTION.txt"},{"type":"EVIDENCE","url":"https://www.exploit-db.com/exploits/42043/"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/mantisbt/mantisbt","events":[{"introduced":"0"},{"last_affected":"a5fe25b9e937af5486d49318c75fbd3e026bf37a"},{"introduced":"ac51f2a22377ec1cef40ae53048327d7ab2df33e"},{"last_affected":"d83c14a9cd3cdd898fd911dd904feacea7340ac6"}],"database_specific":{"cpe":["cpe:2.3:a:mantisbt:mantisbt:*:*:*:*:*:*:*:*","cpe:2.3:a:mantisbt:mantisbt:2.0.0:*:*:*:*:*:*:*","cpe:2.3:a:mantisbt:mantisbt:2.0.1:*:*:*:*:*:*:*","cpe:2.3:a:mantisbt:mantisbt:2.1.0:*:*:*:*:*:*:*","cpe:2.3:a:mantisbt:mantisbt:2.1.1:*:*:*:*:*:*:*","cpe:2.3:a:mantisbt:mantisbt:2.1.2:*:*:*:*:*:*:*","cpe:2.3:a:mantisbt:mantisbt:2.2.0:*:*:*:*:*:*:*","cpe:2.3:a:mantisbt:mantisbt:2.2.2:*:*:*:*:*:*:*","cpe:2.3:a:mantisbt:mantisbt:2.2.3:*:*:*:*:*:*:*","cpe:2.3:a:mantisbt:mantisbt:2.2.4:*:*:*:*:*:*:*","cpe:2.3:a:mantisbt:mantisbt:2.4.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"0"},{"last_affected":"1.3.10"},{"introduced":"2.0.0"},{"last_affected":"2.0.0"},{"introduced":"2.0.1"},{"last_affected":"2.0.1"},{"introduced":"2.1.0"},{"last_affected":"2.1.0"},{"introduced":"2.1.1"},{"last_affected":"2.1.1"},{"introduced":"2.1.2"},{"last_affected":"2.1.2"},{"introduced":"2.2.0"},{"last_affected":"2.2.0"},{"introduced":"2.2.2"},{"last_affected":"2.2.2"},{"introduced":"2.2.3"},{"last_affected":"2.2.3"},{"introduced":"2.2.4"},{"last_affected":"2.2.4"},{"introduced":"2.4.0"},{"last_affected":"2.4.0"}],"source":["CPE_RANGE","CPE_STRING"]}}],"versions":["2.0.0","2.0.1","2.1.0","2.1.1","2.1.2","2.2.0","2.2.2","2.2.3","2.2.4","2.4.0","release-2.4.0","release-1.3.10","release-2.3.0","release-1.3.9","release-1.3.8","release-1.3.7","release-2.2.0","release-1.3.6","release-2.1.0","release-1.3.5","release-2.0.0","release-1.3.4","release-1.3.3","release-1.3.2","release-1.3.1","release-1.3.0","release-1.3.0-rc.2","release-1.3.0-rc.1","release-1.3.0-beta.3","release-1.3.0-beta.2","release-1.3.0-beta.1","release-1.2.0rc1","release-1.2.0a3","release-1.2.0a2","release-1.2.0a1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-7620.json"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"}]}