CVE-2014-9279: Mantisbt

Medium severity, CVSS 5.0. EPSS: 2.1% chance of exploitation in the next 30 days.

The print_test_result function in admin/upgrade_unattended.php in MantisBT 1.1.0a3 through 1.2.x before 1.2.18 allows remote attackers to obtain database credentials via a URL in the hostname parameter and reading the parameters in the response sent to the URL.

Affected products

  • Mantisbt Mantisbt: version 1.0.0 only; version 1.0.1 only; version 1.0.2 only; version 1.0.3 only; version 1.0.4 only; version 1.0.5 only; …

Published 2014-12-08. Last modified 2026-06-17.