Skip to main content

CVE-2014-7146

CVSS Score Not Available
80.39%
HIGH RiskEPSS (99th percentile)

The XmlImportExport plugin in MantisBT 1.2.17 and earlier allows remote attackers to execute arbitrary PHP code via a crafted (1) description field or (2) issuelink attribute in an XML file, which is not properly handled when executing the preg_replace function with the e modifier.

Published: 11/18/2014
Modified: 4/12/2025
Back to CVE Lookup

Vulnerability Summary

EPSS Score (Exploitation Probability)

80.39%HIGH Exploitation Risk
99th percentile

This vulnerability has a 80.39% probability of being exploited in the next 30 days, ranking higher than 99% of all scored CVEs.