CVE-2012-5523: Medium severity centos libreport-plugin-mantisbt vulnerability
core/emailapi.php in MantisBT before 1.2.12 does not properly manage the sending of e-mail notifications about restricted bugs, which might allow remote authenticated users to obtain sensitive information by adding a note to a bug before losing permission to view that bug.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-5523?
CVE-2012-5523 has a medium severity level as it allows remote authenticated users to access sensitive information about restricted bugs.
How do I fix CVE-2012-5523?
To fix CVE-2012-5523, update MantisBT to version 1.2.12 or higher, which addresses this vulnerability.
What software versions are affected by CVE-2012-5523?
CVE-2012-5523 affects MantisBT versions prior to 1.2.12, including all 1.2.11 and earlier versions as well as specific early versions.
What is the impact of CVE-2012-5523?
The impact of CVE-2012-5523 is that users can potentially retrieve sensitive bug information after losing access permissions.
Is CVE-2012-5523 exploitable remotely?
Yes, CVE-2012-5523 is exploitable remotely by authenticated users who have permission to interact with specific bugs.