In MantisBT 2.24.3, SQL Injection can occur in the parameter "access" of the mcprojectget_users function through the API SOAP.