Unrated severityNVD Advisory· Published Nov 18, 2014· Updated May 6, 2026
CVE-2014-7146
CVE-2014-7146
Description
The XmlImportExport plugin in MantisBT 1.2.17 and earlier allows remote attackers to execute arbitrary PHP code via a crafted (1) description field or (2) issuelink attribute in an XML file, which is not properly handled when executing the preg_replace function with the e modifier.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
8- github.com/mantisbt/mantisbt/commit/84017535nvdVendor Advisory
- github.com/mantisbt/mantisbt/commit/bed19db9nvdVendor Advisory
- seclists.org/oss-sec/2014/q4/576nvd
- secunia.com/advisories/62101nvd
- www.debian.org/security/2015/dsa-3120nvd
- www.mantisbt.org/bugs/view.phpnvd
- www.securityfocus.com/bid/70993nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/98572nvd
News mentions
0No linked articles in our index yet.