CVE-2014-8554: Mantisbt

High severity, CVSS 7.5. EPSS: 2.4% chance of exploitation in the next 30 days.

SQL injection vulnerability in the mc_project_get_attachments function in api/soap/mc_project_api.php in MantisBT before 1.2.18 allows remote attackers to execute arbitrary SQL commands via the project_id parameter. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-1609.

Affected products

  • Mantisbt Mantisbt: up to and including 1.2.17; version 0.18.0 only; version 0.19.0 only; version 0.19.0a1 only; version 0.19.0a2 only; version 0.19.1 only; …

Published 2014-11-13. Last modified 2026-06-17.