{"id":"CVE-2019-15715","aliases":["GHSA-v23g-wjvq-2fpf"],"url":"https://o3.security/vulnerability/CVE-2019-15715","summary":"MantisBT Remote Code Execution","details":"MantisBT before 1.3.20 and 2.22.1 allows Post Authentication Command Injection, leading to Remote Code Execution.","published":"2019-10-09T20:15:23.207Z","modified":"2026-08-07T14:52:39.521821Z","cvss":{"score":7.2,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":4,"affectedPackages":[{"ecosystem":"Packagist","name":"mantisbt/mantisbt","fixedVersion":"1.3.20"},{"ecosystem":"Packagist","name":"mantisbt/mantisbt","fixedVersion":"2.22.1"}],"fix":{"url":"https://github.com/mantisbt/mantisbt/commit/5fb979604d88c630343b3eaf2b435cd41918c501","label":"mantisbt/mantisbt@5fb9796"},"references":[{"type":"ADVISORY","url":"https://mantisbt.org/bugs/changelog_page.php?project=mantisbt"},{"type":"REPORT","url":"https://mantisbt.org/bugs/view.php?id=26091"},{"type":"REPORT","url":"https://mantisbt.org/bugs/view.php?id=26162"},{"type":"FIX","url":"https://github.com/mantisbt/mantisbt/commit/5fb979604d88c630343b3eaf2b435cd41918c501"},{"type":"FIX","url":"https://github.com/mantisbt/mantisbt/commit/7092573fac31eff41823f13540324db167c8bd52"},{"type":"FIX","url":"https://github.com/mantisbt/mantisbt/commit/cebfb9acb3686e8904d80bd4bc80720b54ba08e5"},{"type":"FIX","url":"https://github.com/mantisbt/mantisbt/commit/fc7668c8e45db55fc3a4b991ea99d2b80861a14c"},{"type":"EVIDENCE","url":"http://packetstormsecurity.com/files/159219/Mantis-Bug-Tracker-2.3.0-Remote-Code-Execution.html"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T14:52:39.521821Z"}}