CVE-2012-1122: Low severity MantisBT mantisbt vulnerability
bugactiongroup.php in MantisBT before 1.2.9 does not properly check the reportbugthreshold permission of the receiving project when moving a bug report, which allows remote authenticated users with the reportbugthreshold and movebugthreshold privileges for a project to bypass intended access restrictions and move bug reports to a different project.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2012-1122?
CVE-2012-1122 has a moderate severity rating due to the improper permission validation allowing authenticated users to bypass project access controls.
How do I fix CVE-2012-1122?
To fix CVE-2012-1122, upgrade MantisBT to version 1.2.9 or later, which addresses the vulnerability.
Which versions of MantisBT are affected by CVE-2012-1122?
CVE-2012-1122 affects MantisBT versions prior to 1.2.9, including versions from 0.18.0 to 1.2.8.
What is CVE-2012-1122 vulnerability about?
CVE-2012-1122 allows remote authenticated users with specific privileges to move bug reports between projects without proper permission checks.
Who is impacted by CVE-2012-1122?
Users of MantisBT who have report_bug_threshold and move_bug_threshold privileges may exploit the vulnerability to bypass access controls.