{"api_version":"1","generated_at":"2026-07-23T14:20:59+00:00","cve":"CVE-2014-8598","urls":{"html":"https://cve.report/CVE-2014-8598","api":"https://cve.report/api/cve/CVE-2014-8598.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2014-8598","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2014-8598"},"summary":{"title":"CVE-2014-8598","description":"The XML Import/Export plugin in MantisBT 1.2.x does not restrict access, which allows remote attackers to (1) upload arbitrary XML files via the import page or (2) obtain sensitive information via the export page.  NOTE: this issue can be combined with CVE-2014-7146 to execute arbitrary PHP code.","state":"PUBLISHED","assigner":"mitre","published_at":"2014-11-18 15:59:06","updated_at":"2026-05-06 22:30:45"},"problem_types":["CWE-19","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"6.4","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:N","baseScore":6.4,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.mantisbt.org/bugs/view.php?id=17780","name":"http://www.mantisbt.org/bugs/view.php?id=17780","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"0017780: CVE-2014-8598: XML plugin should restrict ability to import data - MantisBT","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/62101","name":"http://secunia.com/advisories/62101","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Security Advisory SA62101 - Debian update for mantis - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.debian.org/security/2015/dsa-3120","name":"http://www.debian.org/security/2015/dsa-3120","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Debian -- Security Information -- DSA-3120-1 mantis","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/70996","name":"http://www.securityfocus.com/bid/70996","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"MantisBT XmlImportExport Plugin CVE-2014-8598 Multiple Security Bypass Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.openwall.com/lists/oss-security/2014/11/07/28","name":"http://www.openwall.com/lists/oss-security/2014/11/07/28","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"oss-security - CVE-2014-8598: MantisBT XML Import/Export plugin unrestricted access","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/98573","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/98573","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/mantisbt/mantisbt/commit/80a15487","name":"https://github.com/mantisbt/mantisbt/commit/80a15487","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"XML plugin: Add config page with access thresholds · mantisbt/mantisbt@80a1548 · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2014-8598","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2014-8598","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2014","cve_id":"8598","vulnerable":"1","versionEndIncluding":"1.2.17","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mantisbt","cpe5":"mantisbt","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T13:25:59.956Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://github.com/mantisbt/mantisbt/commit/80a15487"},{"name":"[oss-security] 20141108 CVE-2014-8598: MantisBT XML Import/Export plugin unrestricted access","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"http://www.openwall.com/lists/oss-security/2014/11/07/28"},{"name":"mantisbt-cve20148598-sec-bypass(98573)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/98573"},{"name":"70996","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/70996"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.mantisbt.org/bugs/view.php?id=17780"},{"name":"62101","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/62101"},{"name":"DSA-3120","tags":["vendor-advisory","x_refsource_DEBIAN","x_transferred"],"url":"http://www.debian.org/security/2015/dsa-3120"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2014-11-07T00:00:00.000Z","descriptions":[{"lang":"en","value":"The XML Import/Export plugin in MantisBT 1.2.x does not restrict access, which allows remote attackers to (1) upload arbitrary XML files via the import page or (2) obtain sensitive information via the export page.  NOTE: this issue can be combined with CVE-2014-7146 to execute arbitrary PHP code."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-09-07T15:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"https://github.com/mantisbt/mantisbt/commit/80a15487"},{"name":"[oss-security] 20141108 CVE-2014-8598: MantisBT XML Import/Export plugin unrestricted access","tags":["mailing-list","x_refsource_MLIST"],"url":"http://www.openwall.com/lists/oss-security/2014/11/07/28"},{"name":"mantisbt-cve20148598-sec-bypass(98573)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/98573"},{"name":"70996","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/70996"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.mantisbt.org/bugs/view.php?id=17780"},{"name":"62101","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/62101"},{"name":"DSA-3120","tags":["vendor-advisory","x_refsource_DEBIAN"],"url":"http://www.debian.org/security/2015/dsa-3120"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2014-8598","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The XML Import/Export plugin in MantisBT 1.2.x does not restrict access, which allows remote attackers to (1) upload arbitrary XML files via the import page or (2) obtain sensitive information via the export page.  NOTE: this issue can be combined with CVE-2014-7146 to execute arbitrary PHP code."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"https://github.com/mantisbt/mantisbt/commit/80a15487","refsource":"CONFIRM","url":"https://github.com/mantisbt/mantisbt/commit/80a15487"},{"name":"[oss-security] 20141108 CVE-2014-8598: MantisBT XML Import/Export plugin unrestricted access","refsource":"MLIST","url":"http://www.openwall.com/lists/oss-security/2014/11/07/28"},{"name":"mantisbt-cve20148598-sec-bypass(98573)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/98573"},{"name":"70996","refsource":"BID","url":"http://www.securityfocus.com/bid/70996"},{"name":"http://www.mantisbt.org/bugs/view.php?id=17780","refsource":"CONFIRM","url":"http://www.mantisbt.org/bugs/view.php?id=17780"},{"name":"62101","refsource":"SECUNIA","url":"http://secunia.com/advisories/62101"},{"name":"DSA-3120","refsource":"DEBIAN","url":"http://www.debian.org/security/2015/dsa-3120"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2014-8598","datePublished":"2014-11-18T15:00:00.000Z","dateReserved":"2014-11-04T00:00:00.000Z","dateUpdated":"2024-08-06T13:25:59.956Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2014-11-18 15:59:06","lastModifiedDate":"2026-05-06 22:30:45","problem_types":["CWE-19","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:N","baseScore":6.4,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:mantisbt:mantisbt:*:*:*:*:*:*:*:*","versionEndIncluding":"1.2.17","matchCriteriaId":"5761D76C-7109-4E94-AEC3-3A6419429A91"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2014","CveId":"8598","Ordinal":"1","Title":"CVE-2014-8598","CVE":"CVE-2014-8598","Year":"2014"},"notes":[{"CveYear":"2014","CveId":"8598","Ordinal":"1","NoteData":"The XML Import/Export plugin in MantisBT 1.2.x does not restrict access, which allows remote attackers to (1) upload arbitrary XML files via the import page or (2) obtain sensitive information via the export page.  NOTE: this issue can be combined with CVE-2014-7146 to execute arbitrary PHP code.","Type":"Description","Title":"CVE-2014-8598"},{"CveYear":"2014","CveId":"8598","Ordinal":"2","NoteData":"2014-11-18","Type":"Other","Title":"Published"},{"CveYear":"2014","CveId":"8598","Ordinal":"3","NoteData":"2017-09-07","Type":"Other","Title":"Modified"}]}}}