MantisBT versions before 1.3.20 and before 2.22.1 contain a post-authentication command-injection vulnerability. An authenticated attacker can inject commands through the vulnerable functionality, resulting in remote code execution on the affected MantisBT instance.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
Repository contains a single Python3 exploit script (CVE-2019-15715.py) plus a README. The script targets CVE-2019-15715 in Mantis Bug Tracker (claimed vulnerable versions <= 2.22.0) by abusing MantisBT’s configuration management to achieve command execution through the relationship/workflow graph feature. Core flow: - Builds a base URL http://<rhost>:<rport><endpoint> and uses a requests.Session for cookie handling. - Authenticates to MantisBT via POST /login.php using provided username/password. - Fetches a CSRF token from /adm_config_report.php, then POSTs to /adm_config_set.php to create/modify: - relationship_graph_enable=1 (enables graphing) - dot_tool=<command> where <command> is: echo <base64> | base64 -d | /bin/bash (URL-encoded), enabling arbitrary command execution. - Triggers execution by requesting /workflow_graph_img.php (graph generation invokes dot_tool). - Attempts cleanup by locating delete tokens in /adm_config_report.php and POSTing to /adm_config_delete.php to remove dot_tool and relationship_graph_enable. Notable observations: - Despite the header claiming “Unauthenticated”, the implementation requires credentials to log in and access admin config pages. - Payload is user-supplied as a base64-encoded reverse shell string; the exploit wraps it in a decode-and-exec bash one-liner. - Endpoints are all standard MantisBT PHP paths; no hardcoded external C2 domains/IPs are present beyond the user-supplied rhost/lhost parameters.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.