CVE-2012-1118: Medium severity MantisBT mantisbt vulnerability
The accesshasbuglevel function in core/accessapi.php in MantisBT before 1.2.9 does not properly restrict access when the privatebugviewthreshold is set to an array, which allows remote attackers to bypass intended restrictions and perform certain operations on private bug reports.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2012-1118?
CVE-2012-1118 is classified as a medium severity vulnerability due to its potential to allow unauthorized access to private bug reports.
How do I fix CVE-2012-1118?
To fix CVE-2012-1118, upgrade MantisBT to version 1.2.9 or later, which addresses this access control issue.
What versions of MantisBT are affected by CVE-2012-1118?
CVE-2012-1118 affects all MantisBT versions prior to 1.2.9, including versions 0.18.0 through 1.2.8.
What kind of attacks can occur due to CVE-2012-1118?
Attackers can exploit CVE-2012-1118 to bypass access restrictions and view or manipulate private bug reports.
Is there any workaround for CVE-2012-1118?
There are no effective workarounds for CVE-2012-1118; the best mitigation is to upgrade to a secure version.