CVE-2014-2238: Mantisbt
Medium severity, CVSS 6.5. EPSS: 11.3% chance of exploitation in the next 30 days.
SQL injection vulnerability in the manage configuration page (adm_config_report.php) in MantisBT 1.2.13 through 1.2.16 allows remote authenticated administrators to execute arbitrary SQL commands via the filter_config_id parameter.
Affected products
- Mantisbt Mantisbt: version 1.2.13 only; version 1.2.14 only; version 1.2.15 only; version 1.2.16 only
Published 2014-03-05. Last modified 2026-06-17.