CVE-2012-2692: Low severity MantisBT mantisbt vulnerability
MantisBT before 1.2.11 does not check the deleteattachmentsthreshold permission when formsecurityvalidation is set to OFF, which allows remote authenticated users with certain privileges to bypass intended access restrictions and delete arbitrary attachments.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2012-2692?
CVE-2012-2692 has a moderate severity rating due to unauthorized deletion of attachments by authenticated users.
How do I fix CVE-2012-2692?
To fix CVE-2012-2692, upgrade MantisBT to version 1.2.11 or later.
Which versions of MantisBT are affected by CVE-2012-2692?
CVE-2012-2692 affects MantisBT versions prior to 1.2.11, including all versions in the 1.2.0 to 1.2.10 range and earlier versions.
What type of access does CVE-2012-2692 allow attackers?
CVE-2012-2692 allows remote authenticated users with certain privileges to bypass restrictions and delete arbitrary attachments.
Is form_security_validation related to CVE-2012-2692?
Yes, CVE-2012-2692 is triggered when form_security_validation is set to OFF, allowing permission checks to be bypassed.