CVE-2014-7146
CVSS Score Not Available
80.39%
HIGH RiskEPSS (99th percentile)
The XmlImportExport plugin in MantisBT 1.2.17 and earlier allows remote attackers to execute arbitrary PHP code via a crafted (1) description field or (2) issuelink attribute in an XML file, which is not properly handled when executing the preg_replace function with the e modifier.
Published: 11/18/2014
Modified: 4/12/2025
Vulnerability Summary
EPSS Score (Exploitation Probability)
80.39%HIGH Exploitation Risk
99th percentile
This vulnerability has a 80.39% probability of being exploited in the next 30 days, ranking higher than 99% of all scored CVEs.