CVE-2014-1609 describes multiple SQL injection vulnerabilities in MantisBT versions prior to 1.2.16, affecting various functions and pages within the bug tracking system. These vulnerabilities allow remote, unauthenticated attackers to execute arbitrary SQL commands, potentially leading to data compromise, integrity issues, and denial of service. With a CVSS score of 7.5 (High), the attack complexity is low, requiring no authentication. There is no evidence of active exploitation, publicly available exploit code, or significant community discussion or media coverage for this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
7.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:* | ||
<= 1.2.15CPE matchmatch criteria | cpe:2.3:a:mantisbt:mantisbt:*:*:*:*:*:*:*:* | ||
1.2.0CPE matchmatch criteria | cpe:2.3:a:mantisbt:mantisbt:1.2.0:*:*:*:*:*:*:* | ||
1.2.0CPE matchmatch criteria | cpe:2.3:a:mantisbt:mantisbt:1.2.0:alpha1:*:*:*:*:*:* | ||
1.2.0CPE matchmatch criteria | cpe:2.3:a:mantisbt:mantisbt:1.2.0:alpha2:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.