CVE-2014-2238: Mantisbt

Medium severity, CVSS 6.5. EPSS: 11.3% chance of exploitation in the next 30 days.

SQL injection vulnerability in the manage configuration page (adm_config_report.php) in MantisBT 1.2.13 through 1.2.16 allows remote authenticated administrators to execute arbitrary SQL commands via the filter_config_id parameter.

Affected products

  • Mantisbt Mantisbt: version 1.2.13 only; version 1.2.14 only; version 1.2.15 only; version 1.2.16 only

Published 2014-03-05. Last modified 2026-06-17.