PT-2012-3095 · Mantisbt · Mantisbt

David Hicks

·

Published

2012-06-29

·

Updated

2021-01-12

·

CVE-2012-1123

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions MantisBT versions prior to 1.2.9
Description The issue allows remote attackers to bypass authentication. This is due to the mci check login function in the SOAP API, which permits authentication bypass via a null password.
Recommendations For versions prior to 1.2.9, update to version 1.2.9 or later to resolve the issue. As a temporary workaround, consider restricting access to the SOAP API until the update is applied.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2012-1123
DSA-2500-1

Affected Products

Mantisbt