CVE Vulnerabilities

CVE-2012-2692

Published: Jun 17, 2012 | Modified: Jan 12, 2021
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
3.6 LOW
AV:N/AC:H/Au:S/C:N/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

MantisBT before 1.2.11 does not check the delete_attachments_threshold permission when form_security_validation is set to OFF, which allows remote authenticated users with certain privileges to bypass intended access restrictions and delete arbitrary attachments.

Affected Software

Name Vendor Start Version End Version
Mantisbt Mantisbt * 1.2.10 (including)
Mantisbt Mantisbt 0.18.0 (including) 0.18.0 (including)
Mantisbt Mantisbt 0.19.0 (including) 0.19.0 (including)
Mantisbt Mantisbt 0.19.0-a1 (including) 0.19.0-a1 (including)
Mantisbt Mantisbt 0.19.0-a2 (including) 0.19.0-a2 (including)
Mantisbt Mantisbt 0.19.0-rc1 (including) 0.19.0-rc1 (including)
Mantisbt Mantisbt 0.19.1 (including) 0.19.1 (including)
Mantisbt Mantisbt 0.19.2 (including) 0.19.2 (including)
Mantisbt Mantisbt 0.19.3 (including) 0.19.3 (including)
Mantisbt Mantisbt 0.19.4 (including) 0.19.4 (including)
Mantisbt Mantisbt 0.19.5 (including) 0.19.5 (including)
Mantisbt Mantisbt 1.0.0 (including) 1.0.0 (including)
Mantisbt Mantisbt 1.0.0-a1 (including) 1.0.0-a1 (including)
Mantisbt Mantisbt 1.0.0-a2 (including) 1.0.0-a2 (including)
Mantisbt Mantisbt 1.0.0-a3 (including) 1.0.0-a3 (including)
Mantisbt Mantisbt 1.0.0-rc1 (including) 1.0.0-rc1 (including)
Mantisbt Mantisbt 1.0.0-rc2 (including) 1.0.0-rc2 (including)
Mantisbt Mantisbt 1.0.0-rc3 (including) 1.0.0-rc3 (including)
Mantisbt Mantisbt 1.0.0-rc4 (including) 1.0.0-rc4 (including)
Mantisbt Mantisbt 1.0.0-rc5 (including) 1.0.0-rc5 (including)
Mantisbt Mantisbt 1.0.1 (including) 1.0.1 (including)
Mantisbt Mantisbt 1.0.2 (including) 1.0.2 (including)
Mantisbt Mantisbt 1.0.3 (including) 1.0.3 (including)
Mantisbt Mantisbt 1.0.4 (including) 1.0.4 (including)
Mantisbt Mantisbt 1.0.5 (including) 1.0.5 (including)
Mantisbt Mantisbt 1.0.6 (including) 1.0.6 (including)
Mantisbt Mantisbt 1.0.7 (including) 1.0.7 (including)
Mantisbt Mantisbt 1.0.8 (including) 1.0.8 (including)
Mantisbt Mantisbt 1.1.0 (including) 1.1.0 (including)
Mantisbt Mantisbt 1.1.1 (including) 1.1.1 (including)
Mantisbt Mantisbt 1.1.2 (including) 1.1.2 (including)
Mantisbt Mantisbt 1.1.4 (including) 1.1.4 (including)
Mantisbt Mantisbt 1.1.5 (including) 1.1.5 (including)
Mantisbt Mantisbt 1.1.6 (including) 1.1.6 (including)
Mantisbt Mantisbt 1.1.7 (including) 1.1.7 (including)
Mantisbt Mantisbt 1.1.8 (including) 1.1.8 (including)
Mantisbt Mantisbt 1.2.0 (including) 1.2.0 (including)
Mantisbt Mantisbt 1.2.0-alpha1 (including) 1.2.0-alpha1 (including)
Mantisbt Mantisbt 1.2.0-alpha2 (including) 1.2.0-alpha2 (including)
Mantisbt Mantisbt 1.2.1 (including) 1.2.1 (including)
Mantisbt Mantisbt 1.2.2 (including) 1.2.2 (including)
Mantisbt Mantisbt 1.2.3 (including) 1.2.3 (including)
Mantisbt Mantisbt 1.2.4 (including) 1.2.4 (including)
Mantisbt Mantisbt 1.2.5 (including) 1.2.5 (including)
Mantisbt Mantisbt 1.2.6 (including) 1.2.6 (including)
Mantisbt Mantisbt 1.2.7 (including) 1.2.7 (including)
Mantisbt Mantisbt 1.2.8 (including) 1.2.8 (including)
Mantisbt Mantisbt 1.2.9 (including) 1.2.9 (including)
Mantis Ubuntu hardy *
Mantis Ubuntu lucid *
Mantis Ubuntu natty *
Mantis Ubuntu oneiric *
Mantis Ubuntu precise *
Mantis Ubuntu upstream *

References