PT-2012-3092 · Mantisbt · Mantisbt

David Hicks

·

Published

2012-06-29

·

Updated

2021-01-12

·

CVE-2012-1120

CVSS v2.0

3.6

Low

VectorAV:N/AC:H/Au:S/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions MantisBT versions prior to 1.2.9
Description The issue concerns the SOAP API in MantisBT, where it fails to properly enforce certain permissions, specifically bugnote allow user edit delete and delete bug threshold. This allows remote authenticated users with read and write SOAP API privileges to delete arbitrary bug reports and bug notes.
Recommendations For versions prior to 1.2.9, update to version 1.2.9 or later to resolve the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2012-1120
DSA-2500-1

Affected Products

Mantisbt