PoC Index

CVE-2014-2238

MEDIUM 6.5EPSS 11.3%

SQL injection vulnerability in the manage configuration page (adm_config_report.php) in MantisBT 1.2.13 through 1.2.16 allows remote authenticated administrators to execute arbitrary SQL commands via the filter_config_id parameter.

CVSS v2.0
6.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
EPSS
11.31% chance of exploitation in the next 30 days, 96th percentile
Published
2014-03-05
Updated
2024-08-06

Metasploit modules (1)

References

Related