7.5
CVSSv2

CVE-2012-2691

Published: 17/06/2012 Updated: 12/01/2021
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The mc_issue_note_update function in the SOAP API in MantisBT prior to 1.2.11 does not properly check privileges, which allows remote attackers with bug reporting privileges to edit arbitrary bugnotes via a SOAP request.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mantisbt mantisbt 1.2.3

mantisbt mantisbt 1.2.2

mantisbt mantisbt 1.1.7

mantisbt mantisbt 1.1.6

mantisbt mantisbt 1.2.0

mantisbt mantisbt 1.1.0

mantisbt mantisbt 1.0.1

mantisbt mantisbt 1.0.0

mantisbt mantisbt 0.19.0

mantisbt mantisbt 0.18.0

mantisbt mantisbt 1.2.8

mantisbt mantisbt 1.2.7

mantisbt mantisbt 1.2.6

mantisbt mantisbt 1.1.9

mantisbt mantisbt 1.1.3

mantisbt mantisbt 1.1.2

mantisbt mantisbt 1.0.5

mantisbt mantisbt 1.0.4

mantisbt mantisbt 0.19.3

mantisbt mantisbt 0.19.2

mantisbt mantisbt

mantisbt mantisbt 1.2.9

mantisbt mantisbt 1.2.1

mantisbt mantisbt 1.1.5

mantisbt mantisbt 1.1.4

mantisbt mantisbt 1.0.9

mantisbt mantisbt 1.0.7

mantisbt mantisbt 0.19.5

mantisbt mantisbt 0.19.4

mantisbt mantisbt 1.2.5

mantisbt mantisbt 1.2.4

mantisbt mantisbt 1.1.8

mantisbt mantisbt 1.1.1

mantisbt mantisbt 1.0.8

mantisbt mantisbt 1.0.3

mantisbt mantisbt 1.0.2

mantisbt mantisbt 0.19.1