CVE-2014-7146

MantisBT <1.2.17 - RCE

Title source: llm

Description

The XmlImportExport plugin in MantisBT 1.2.17 and earlier allows remote attackers to execute arbitrary PHP code via a crafted (1) description field or (2) issuelink attribute in an XML file, which is not properly handled when executing the preg_replace function with the e modifier.

Exploits (3)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotephp
https://www.exploit-db.com/exploits/35283
exploitdb WORKING POC
rubywebappsmultiple
https://www.exploit-db.com/exploits/41685
metasploit WORKING POC GREAT
by Egidio Romano · rubypocphp
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/mantisbt_php_exec.rb

Scores

EPSS 0.8039
EPSS Percentile 99.1%

Details

CWE
CWE-20
Status published
Products (1)
mantisbt/mantisbt 1.2.17
Published Nov 18, 2014
Tracked Since Feb 18, 2026