CVE-2014-1608: SQL Injection

Published Feb 10, 2014
·
Updated

SQL injection issues were discovered in MantisBT, an open source issue tracker.

CVE-2014-1608 patch: https://github.com/mantisbt/mantisbt/commit/00b4c17088fa56594d85fe46b6c6057bb3421102

CVE-2014-1609 patch: https://github.com/mantisbt/mantisbt/commit/7efe0175f0853e18ebfacedfd2374c4179028b3f

It was reported that versions 1.1.0a4 to 1.2.15 are affected.

References: http://www.ocert.org/advisories/ocert-2014-001.html

Other sources

SQL injection vulnerability in the mcifileget function in api/soap/mcfileapi.php in MantisBT before 1.2.16 allows remote attackers to execute arbitrary SQL commands via a crafted envelope tag in a mcissueattachmentget SOAP request.

MITRE

Affected Software

21 affected components
MantisBT mantisbt<=1.2.15
MantisBT mantisbt=1.2.0
MantisBT mantisbt=1.2.0-alpha1
MantisBT mantisbt=1.2.0-alpha2
MantisBT mantisbt=1.2.0-alpha3
MantisBT mantisbt=1.2.0-rc1
MantisBT mantisbt=1.2.0-rc2
MantisBT mantisbt=1.2.1
MantisBT mantisbt=1.2.2
MantisBT mantisbt=1.2.3
MantisBT mantisbt=1.2.4
MantisBT mantisbt=1.2.5
MantisBT mantisbt=1.2.6
MantisBT mantisbt=1.2.7
MantisBT mantisbt=1.2.8
MantisBT mantisbt=1.2.9
MantisBT mantisbt=1.2.10
MantisBT mantisbt=1.2.11
MantisBT mantisbt=1.2.13
MantisBT mantisbt=1.2.14
Debian Debian Linux=7.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade mantisbt/mantisbt to a version that resolves this vulnerability.

    Fixed in 1.2.16
  2. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Patch CVE-2014-1608
  3. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Patch CVE-2014-1609

Event History

Feb 10, 2014
Data Sourced
via Red Hat·03:24 AM
DescriptionSeverityAffected Software
Mar 18, 2014
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Data Sourced
via NVD·05:03 PM
RemedyDescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2014-1608?

CVE-2014-1608 is classified as a medium severity vulnerability due to SQL injection risks.

2

How do I fix CVE-2014-1608?

To fix CVE-2014-1608, upgrade MantisBT to the latest version that addresses the vulnerability.

3

What software versions are affected by CVE-2014-1608?

CVE-2014-1608 affects MantisBT versions up to 1.2.15, including several earlier releases.

4

What impact does CVE-2014-1608 have on systems?

CVE-2014-1608 can allow attackers to execute arbitrary SQL commands, potentially compromising the database.

5

Is there a patch available for CVE-2014-1608?

Yes, a patch for CVE-2014-1608 has been released and is available in the latest version of MantisBT.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203