5.5
CVSSv2

CVE-2012-5522

Published: 16/11/2012 Updated: 12/01/2021
CVSS v2 Base Score: 5.5 | Impact Score: 4.9 | Exploitability Score: 8
VMScore: 490
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:N

Vulnerability Summary

MantisBT prior to 1.2.12 does not use an expected default value during decisions about whether a user may modify the status of a bug, which allows remote authenticated users to bypass intended access restrictions and make status changes by leveraging a blank value for a per-status setting.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mantisbt mantisbt 1.2.10

mantisbt mantisbt 1.2.9

mantisbt mantisbt 1.2.1

mantisbt mantisbt 1.2.0

mantisbt mantisbt 1.1.3

mantisbt mantisbt 1.1.2

mantisbt mantisbt 1.1.0

mantisbt mantisbt 1.0.3

mantisbt mantisbt 1.0.2

mantisbt mantisbt 1.0.0

mantisbt mantisbt 0.19.0

mantisbt mantisbt 0.19.3

mantisbt mantisbt 0.19.5

mantisbt mantisbt 1.2.6

mantisbt mantisbt 1.2.5

mantisbt mantisbt 1.1.4

mantisbt mantisbt 1.1.5

mantisbt mantisbt 1.0.7

mantisbt mantisbt 1.0.4

mantisbt mantisbt 0.19.1

mantisbt mantisbt 1.2.8

mantisbt mantisbt 1.2.7

mantisbt mantisbt 1.1.9

mantisbt mantisbt 1.1.6

mantisbt mantisbt 1.1.7

mantisbt mantisbt 1.0.1

mantisbt mantisbt 1.0.6

mantisbt mantisbt 1.0.9

mantisbt mantisbt 0.18.0

mantisbt mantisbt

mantisbt mantisbt 1.2.4

mantisbt mantisbt 1.2.3

mantisbt mantisbt 1.2.2

mantisbt mantisbt 1.1.1

mantisbt mantisbt 1.1.8

mantisbt mantisbt 1.0.8

mantisbt mantisbt 1.0.5

mantisbt mantisbt 0.19.2

mantisbt mantisbt 0.19.4