VDB

CVE-2014-7146

CVE-2014-7146 PUBLISHED KEV CVSS 7.5 HIGH

The XmlImportExport plugin in MantisBT 1.2.17 and earlier allows remote attackers to execute arbitrary PHP code via a crafted (1) description field or (2) issuelink attribute in an XML file, which is not properly handled when executing the preg_replace function with the e modifier.

EPSS 50.56% · 98.8th percentile

Risk Scores

CVSS 2.0
7.5
EPSS Score
50.56%
98.8th percentile

Affected Products

VendorProductVersions
mantisbtmantisbt1.2.17
n/an/an/a

Timeline

  • Nov 16, 2014 PoC Published
  • Nov 18, 2014 PoC Published
  • Nov 18, 2014 PoC Published
  • Nov 18, 2014 CVE Published
  • Jan 1, 2015 PoC Published
  • Mar 23, 2017 PoC Published
  • May 29, 2018 PoC Published
  • Feb 4, 2022 EPSS Score
  • Mar 29, 2022 EPSS Score
  • May 17, 2022 CVE Updated
  • May 20, 2022 EPSS Score
  • Jul 12, 2022 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›