← Back

CVE-2014-8553

nvd nist
Published: Dec 17, 2014Modified: May 6, 2026

JSON object

Loading...
5.0
Vector
AV:N/AC:L/Au:N/C:P/I:N/A:N
Exploitability: 10.0 / Impact: 2.9
Source: NVD

Description

The mci_account_get_array_by_id function in api/soap/mc_account_api.php in MantisBT before 1.2.18 allows remote attackers to obtain sensitive information via a (1) mc_project_get_users, (2) mc_issue_get, (3) mc_filter_get_issues, or (4) mc_project_get_issues SOAP request.

Affected (1)

Products: Mantisbt: Mantisbt
1 product
Mantisbt
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 1.2.17

References (16)

Timeline

No history available yet.