CVE

Id
104435  
CVE No.
CVE-2017-7615  
Status
Candidate  
Description
MantisBT through 2.3.0 allows arbitrary password reset and unauthenticated admin access via an empty confirm_hash value to verify.php.  
Phase
Assigned (20170409)  
Votes
None (candidate not yet proposed)  
Comments