CVE-2014-9279: Mantisbt
Medium severity, CVSS 5.0. EPSS: 2.1% chance of exploitation in the next 30 days.
The print_test_result function in admin/upgrade_unattended.php in MantisBT 1.1.0a3 through 1.2.x before 1.2.18 allows remote attackers to obtain database credentials via a URL in the hostname parameter and reading the parameters in the response sent to the URL.
Affected products
- Mantisbt Mantisbt: version 1.0.0 only; version 1.0.1 only; version 1.0.2 only; version 1.0.3 only; version 1.0.4 only; version 1.0.5 only; …
Published 2014-12-08. Last modified 2026-06-17.