CVE-2013-1930: Input Validation
Published Oct 31, 2019
·Updated
MantisBT 1.2.12 before 1.2.15 allows authenticated users to by the workflow restriction and close issues.
Affected Software
4 affected components
debian/mantis
MantisBT mantisbt>=1.2.12<1.2.15
Fedoraproject Fedora=17
Fedoraproject Fedora=18
Event History
Oct 31, 2019
CVE Published
via MITRE·07:05 PM
Data Sourced
via MITRE·07:05 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2013-1930?
The severity of CVE-2013-1930 is medium with a CVSS score of 4.3.
2
How can authenticated users exploit CVE-2013-1930 in MantisBT?
Authenticated users can bypass the workflow restriction and close issues in MantisBT before version 1.2.15.
3
What versions of MantisBT are affected by CVE-2013-1930?
CVE-2013-1930 affects MantisBT versions 1.2.12 to 1.2.15.
4
Are there any known remedies for CVE-2013-1930 in Debian Mantis package?
There are no known remedies for CVE-2013-1930 in the Debian Mantis package.
5
Where can I find more information about CVE-2013-1930?
More information about CVE-2013-1930 can be found at the following references: [1](http://lists.fedoraproject.org/pipermail/package-announce/2013-April/103438.html), [2](http://lists.fedoraproject.org/pipermail/package-announce/2013-April/103459.html), [3](http://www.openwall.com/lists/oss-security/2013/04/06/4)