CVE-2014-8598
Summary
| CVE | CVE-2014-8598 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-11-18 15:59:06 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | The XML Import/Export plugin in MantisBT 1.2.x does not restrict access, which allows remote attackers to (1) upload arbitrary XML files via the import page or (2) obtain sensitive information via the export page. NOTE: this issue can be combined with CVE-2014-7146 to execute arbitrary PHP code. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
NoneAV:N/AC:L/Au:N/C:P/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 0017780: CVE-2014-8598: XML plugin should restrict ability to import data - MantisBT | af854a3a-2127-422b-91ae-364da2661108 | www.mantisbt.org | Vendor Advisory |
| Security Advisory SA62101 - Debian update for mantis - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Debian -- Security Information -- DSA-3120-1 mantis | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| MantisBT XmlImportExport Plugin CVE-2014-8598 Multiple Security Bypass Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| oss-security - CVE-2014-8598: MantisBT XML Import/Export plugin unrestricted access | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| XML plugin: Add config page with access thresholds · mantisbt/mantisbt@80a1548 · GitHub | af854a3a-2127-422b-91ae-364da2661108 | github.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.