CVE-2019-15715
HIGHMantisBT < 1.3.20 - Authenticated Remote Code Execution via Command Injection
Title source: llmExploitation Summary
EIP tracks 4 public exploits for CVE-2019-15715. PoCs published by Nikolas Geiselman, jonathan-corbin, mcornaglia.
AI-analyzed exploit summary This exploit chains CVE-2017-7615 (password reset) and CVE-2019-15715 (command injection) to achieve unauthenticated RCE in Mantis Bug Tracker 2.3.0. It resets the admin password, logs in, configures malicious settings, and triggers a reverse shell.
Description
MantisBT before 1.3.20 and 2.22.1 allows Post Authentication Command Injection, leading to Remote Code Execution.
Exploits (4)
This exploit chains CVE-2017-7615 (password reset) and CVE-2019-15715 (command injection) to achieve unauthenticated RCE in Mantis Bug Tracker 2.3.0. It resets the admin password, logs in, configures malicious settings, and triggers a reverse shell.
This repository contains a functional exploit for CVE-2019-15715, which allows authenticated remote code execution in MantisBT via command injection in the `dot_tool` configuration option. The exploit requires admin credentials and demonstrates the vulnerability by setting up a reverse shell.
This repository contains a functional Python exploit for CVE-2019-15715, which achieves post-authentication remote code execution (RCE) in MantisBT by injecting a malicious `dot_tool` configuration. The exploit automates the process of authenticating as an admin, setting the required configurations, triggering the payload via `workflow_graph_img.php`, and cleaning up the injected configurations.
This repository contains a functional Python exploit for CVE-2019-15715, targeting Mantis Bug Tracker versions <=2.22.0. The exploit leverages unauthenticated remote code execution by manipulating configuration options to inject a reverse shell payload.
References (8)
Scores
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H