First published: Wed Oct 09 2019(Updated: )
MantisBT before 1.3.20 and 2.22.1 allows Post Authentication Command Injection, leading to Remote Code Execution.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mantisbt Mantisbt | >=1.0.0<1.3.20 | |
Mantisbt Mantisbt | >=2.0.0<2.22.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-15715 is a vulnerability in MantisBT versions before 1.3.20 and 2.22.1 that allows Post Authentication Command Injection, leading to Remote Code Execution.
CVE-2019-15715 has a severity score of 7.2, which is considered high.
CVE-2019-15715 affects MantisBT versions before 1.3.20 and 2.22.1, allowing Post Authentication Command Injection, leading to Remote Code Execution.
To fix CVE-2019-15715, upgrade MantisBT to version 1.3.20 or 2.22.1 or later.
More information about CVE-2019-15715 can be found at the following references: [Link 1](http://packetstormsecurity.com/files/159219/Mantis-Bug-Tracker-2.3.0-Remote-Code-Execution.html), [Link 2](https://github.com/mantisbt/mantisbt/commit/5fb979604d88c630343b3eaf2b435cd41918c501), [Link 3](https://github.com/mantisbt/mantisbt/commit/7092573fac31eff41823f13540324db167c8bd52).