CVE-2014-8554: SQL Injection
SQL injection vulnerability in the mcprojectgetattachments function in api/soap/mcprojectapi.php in MantisBT before 1.2.18 allows remote attackers to execute arbitrary SQL commands via the projectid parameter. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-1609.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-8554?
CVE-2014-8554 is classified as a high severity SQL injection vulnerability that can allow remote attackers to execute arbitrary SQL commands.
How do I fix CVE-2014-8554?
To fix CVE-2014-8554, upgrade MantisBT to version 1.2.18 or later, which addresses the SQL injection vulnerability.
What versions of MantisBT are affected by CVE-2014-8554?
CVE-2014-8554 affects all MantisBT versions prior to 1.2.18, including versions 0.18.0 through 1.2.16.
What is the impact of exploiting CVE-2014-8554?
Exploiting CVE-2014-8554 can lead to unauthorized access to the database, allowing attackers to manipulate data or obtain sensitive information.
Is there a known exploit for CVE-2014-8554?
Yes, public knowledge of the vulnerability suggests that exploit methods may exist, highlighting the importance of applying the necessary patches.