SQL injection vulnerability in the mc_project_get_attachments function in api/soap/mc_project_api.php in MantisBT before 1.2.18 allows remote attackers to execute arbitrary SQL commands via the project_id parameter. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-1609.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2014-11-13 21:32
Updated : 2021-01-12 18:05
NVD link : CVE-2014-8554
Mitre link : CVE-2014-8554
CVE.ORG link : CVE-2014-8554
JSON object : View
Products Affected
mantisbt
- mantisbt
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')