Total vulnerabilities in the database
MantisBT through 2.3.0 allows arbitrary password reset and unauthenticated admin access via an empty confirm_hash value to verify.php.
CVSS v3:
CVSS v2:
CWEs:
OWASP TOP 10: