CVE-2014-7146: Input Validation
The XmlImportExport plugin in MantisBT 1.2.17 and earlier allows remote attackers to execute arbitrary PHP code via a crafted (1) description field or (2) issuelink attribute in an XML file, which is not properly handled when executing the pregreplace function with the e modifier.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-7146?
CVE-2014-7146 has a high severity rating due to its potential to allow remote code execution.
How do I fix CVE-2014-7146?
To fix CVE-2014-7146, upgrade to MantisBT version 1.2.18 or later, where the vulnerability has been addressed.
What software is affected by CVE-2014-7146?
CVE-2014-7146 affects MantisBT versions 1.2.17 and earlier.
What type of attack is associated with CVE-2014-7146?
CVE-2014-7146 is associated with remote code execution attacks through crafted XML files.
How can I mitigate the risk of CVE-2014-7146?
Mitigation for CVE-2014-7146 includes applying software patches and implementing security measures to validate XML input.