PT-2012-3092 · Mantisbt · Mantisbt

David Hicks

·

Publicado

2012-06-29

·

Atualizado

2021-01-12

·

CVE-2012-1120

CVSS v2.0

3.6

Baixa

VetorAV:N/AC:H/Au:S/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions MantisBT versions prior to 1.2.9
Description The issue concerns the SOAP API in MantisBT, where it fails to properly enforce certain permissions, specifically bugnote allow user edit delete and delete bug threshold. This allows remote authenticated users with read and write SOAP API privileges to delete arbitrary bug reports and bug notes.
Recommendations For versions prior to 1.2.9, update to version 1.2.9 or later to resolve the issue.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2012-1120
DSA-2500-1

Produtos afetados

Mantisbt