CVE-2014-2238

MantisBT 1.2.13-1.2.16 - Authenticated SQL Injection via filter_config_id Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2014-2238. PoCs published by Jakub Galczyk, including Metasploit module auxiliary/gather/mantisbt_admin_sqli.

AI-analyzed exploit summary This Metasploit module exploits a SQL injection vulnerability in MantisBT versions 1.2.13 through 1.2.16, allowing an authenticated admin to read arbitrary files via a crafted POST request to the adm_config_report.php endpoint.

Description

SQL injection vulnerability in the manage configuration page (adm_config_report.php) in MantisBT 1.2.13 through 1.2.16 allows remote authenticated administrators to execute arbitrary SQL commands via the filter_config_id parameter.

Exploits (1)

metasploit WORKING POC
by Jakub Galczyk · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/gather/mantisbt_admin_sqli.rb

This Metasploit module exploits a SQL injection vulnerability in MantisBT versions 1.2.13 through 1.2.16, allowing an authenticated admin to read arbitrary files via a crafted POST request to the adm_config_report.php endpoint.

Classification
Working Poc 100%
Attack Type
Sqli
Complexity
Moderate
Reliability
Reliable
Target: MantisBT 1.2.13 to 1.2.16
Auth required
Prerequisites: Admin credentials for MantisBT · Network access to the target
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
Mailing List mailing-list x_refsource_mlist
http://seclists.org/oss-sec/2014/q1/456
Patch mailing-list x_refsource_mlist
http://seclists.org/oss-sec/2014/q1/490
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/65903
Vendor Advisory x_refsource_confirm
http://mantisbt.domainunion.de/bugs/view.php?id=17055
Vendor Advisory x_refsource_confirm
http://www.mantisbt.org/blog/?p=288
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/91563

Scores

EPSS 0.1131
EPSS Percentile 95.4%

Details

CWE
CWE-89
Status published
Products (4)
mantisbt/mantisbt 1.2.13
mantisbt/mantisbt 1.2.14
mantisbt/mantisbt 1.2.15
mantisbt/mantisbt 1.2.16
Published Mar 05, 2014
Tracked Since Feb 18, 2026