CVE Vulnerabilities

CVE-2012-5523

Published: Nov 16, 2012 | Modified: Jan 12, 2021
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

core/email_api.php in MantisBT before 1.2.12 does not properly manage the sending of e-mail notifications about restricted bugs, which might allow remote authenticated users to obtain sensitive information by adding a note to a bug before losing permission to view that bug.

Affected Software

Name Vendor Start Version End Version
Mantisbt Mantisbt * 1.2.11 (including)
Mantisbt Mantisbt 0.18.0 (including) 0.18.0 (including)
Mantisbt Mantisbt 0.19.0 (including) 0.19.0 (including)
Mantisbt Mantisbt 0.19.0-a1 (including) 0.19.0-a1 (including)
Mantisbt Mantisbt 0.19.0-a2 (including) 0.19.0-a2 (including)
Mantisbt Mantisbt 0.19.0-rc1 (including) 0.19.0-rc1 (including)
Mantisbt Mantisbt 0.19.1 (including) 0.19.1 (including)
Mantisbt Mantisbt 0.19.2 (including) 0.19.2 (including)
Mantisbt Mantisbt 0.19.3 (including) 0.19.3 (including)
Mantisbt Mantisbt 0.19.4 (including) 0.19.4 (including)
Mantisbt Mantisbt 0.19.5 (including) 0.19.5 (including)
Mantisbt Mantisbt 1.0.0 (including) 1.0.0 (including)
Mantisbt Mantisbt 1.0.0-a1 (including) 1.0.0-a1 (including)
Mantisbt Mantisbt 1.0.0-a2 (including) 1.0.0-a2 (including)
Mantisbt Mantisbt 1.0.0-a3 (including) 1.0.0-a3 (including)
Mantisbt Mantisbt 1.0.0-rc1 (including) 1.0.0-rc1 (including)
Mantisbt Mantisbt 1.0.0-rc2 (including) 1.0.0-rc2 (including)
Mantisbt Mantisbt 1.0.0-rc3 (including) 1.0.0-rc3 (including)
Mantisbt Mantisbt 1.0.0-rc4 (including) 1.0.0-rc4 (including)
Mantisbt Mantisbt 1.0.0-rc5 (including) 1.0.0-rc5 (including)
Mantisbt Mantisbt 1.0.1 (including) 1.0.1 (including)
Mantisbt Mantisbt 1.0.2 (including) 1.0.2 (including)
Mantisbt Mantisbt 1.0.3 (including) 1.0.3 (including)
Mantisbt Mantisbt 1.0.4 (including) 1.0.4 (including)
Mantisbt Mantisbt 1.0.5 (including) 1.0.5 (including)
Mantisbt Mantisbt 1.0.6 (including) 1.0.6 (including)
Mantisbt Mantisbt 1.0.7 (including) 1.0.7 (including)
Mantisbt Mantisbt 1.0.8 (including) 1.0.8 (including)
Mantisbt Mantisbt 1.0.9 (including) 1.0.9 (including)
Mantisbt Mantisbt 1.1.0 (including) 1.1.0 (including)
Mantisbt Mantisbt 1.1.0-a1 (including) 1.1.0-a1 (including)
Mantisbt Mantisbt 1.1.0-a2 (including) 1.1.0-a2 (including)
Mantisbt Mantisbt 1.1.0-a3 (including) 1.1.0-a3 (including)
Mantisbt Mantisbt 1.1.0-a4 (including) 1.1.0-a4 (including)
Mantisbt Mantisbt 1.1.0-rc1 (including) 1.1.0-rc1 (including)
Mantisbt Mantisbt 1.1.0-rc2 (including) 1.1.0-rc2 (including)
Mantisbt Mantisbt 1.1.0-rc3 (including) 1.1.0-rc3 (including)
Mantisbt Mantisbt 1.1.1 (including) 1.1.1 (including)
Mantisbt Mantisbt 1.1.2 (including) 1.1.2 (including)
Mantisbt Mantisbt 1.1.3 (including) 1.1.3 (including)
Mantisbt Mantisbt 1.1.4 (including) 1.1.4 (including)
Mantisbt Mantisbt 1.1.5 (including) 1.1.5 (including)
Mantisbt Mantisbt 1.1.6 (including) 1.1.6 (including)
Mantisbt Mantisbt 1.1.7 (including) 1.1.7 (including)
Mantisbt Mantisbt 1.1.8 (including) 1.1.8 (including)
Mantisbt Mantisbt 1.1.9 (including) 1.1.9 (including)
Mantisbt Mantisbt 1.2.0 (including) 1.2.0 (including)
Mantisbt Mantisbt 1.2.0-alpha1 (including) 1.2.0-alpha1 (including)
Mantisbt Mantisbt 1.2.0-alpha2 (including) 1.2.0-alpha2 (including)
Mantisbt Mantisbt 1.2.0-alpha3 (including) 1.2.0-alpha3 (including)
Mantisbt Mantisbt 1.2.0-rc1 (including) 1.2.0-rc1 (including)
Mantisbt Mantisbt 1.2.0-rc2 (including) 1.2.0-rc2 (including)
Mantisbt Mantisbt 1.2.1 (including) 1.2.1 (including)
Mantisbt Mantisbt 1.2.2 (including) 1.2.2 (including)
Mantisbt Mantisbt 1.2.3 (including) 1.2.3 (including)
Mantisbt Mantisbt 1.2.4 (including) 1.2.4 (including)
Mantisbt Mantisbt 1.2.5 (including) 1.2.5 (including)
Mantisbt Mantisbt 1.2.6 (including) 1.2.6 (including)
Mantisbt Mantisbt 1.2.7 (including) 1.2.7 (including)
Mantisbt Mantisbt 1.2.8 (including) 1.2.8 (including)
Mantisbt Mantisbt 1.2.9 (including) 1.2.9 (including)
Mantisbt Mantisbt 1.2.10 (including) 1.2.10 (including)

References