Junglewise Threat Intelligence

CVE-2026-47142: MantisBT SQL injection in history_order configuration

CVE-2026-47142 · Severity: high · CVSS 4 · Published 2026-07-15

Technologies: mantisbt/mantisbt (Packagist), MantisBT. Vendors: Packagist, MantisBT.

Executive brief

MantisBT, a popular open-source bug tracking system, is vulnerable to a security flaw that allows an administrator to inject malicious database commands. By modifying a specific configuration setting, an attacker can steal sensitive information from the entire database, including user passwords and private issue data. In certain server configurations, this could even allow the attacker to take full control of the web server.

Technical details

A SQL injection vulnerability exists in MantisBT versions 2.28.3 and earlier within 'core/history_api.php'. The 'history_order' configuration value is concatenated directly into a SQL 'ORDER BY' clause without sanitization or whitelist validation. An attacker with administrative privileges can set this value via the web UI or REST API. The payload is executed whenever any authenticated user views a bug with history entries. This can lead to the extraction of sensitive data (credentials, API tokens) or Remote Code Execution (RCE) if the database user has the 'FILE' privilege, enabling the creation of a web shell.

Affected products

  • MantisBT MantisBT <= 2.28.3

Timeline

  • 2026-07-15: disclosed
  • 2026-07-15: advisory
  • 2026-07-15: patched: Fixed in version 2.28.4

References

Related threats