SQL injection vulnerability in the mc_project_get_attachments function in api/soap/mc_project_api.php in MantisBT before 1.2.18 allows remote attackers to execute arbitrary SQL commands via the project_id parameter. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-1609.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2014-11-13 13:32
Updated : 2021-01-12 10:05
NVD link : CVE-2014-8554
Mitre link : CVE-2014-8554
JSON object : View
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Products Affected
mantisbt
- mantisbt