5.5
CVSSv2

CVE-2012-5523

Published: 16/11/2012 Updated: 12/01/2021
CVSS v2 Base Score: 5.5 | Impact Score: 4.9 | Exploitability Score: 8
VMScore: 490
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:N

Vulnerability Summary

core/email_api.php in MantisBT prior to 1.2.12 does not properly manage the sending of e-mail notifications about restricted bugs, which might allow remote authenticated users to obtain sensitive information by adding a note to a bug before losing permission to view that bug.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mantisbt mantisbt 1.2.10

mantisbt mantisbt 1.2.9

mantisbt mantisbt 1.2.2

mantisbt mantisbt 1.2.1

mantisbt mantisbt 1.1.3

mantisbt mantisbt 1.1.2

mantisbt mantisbt 1.1.0

mantisbt mantisbt 1.0.0

mantisbt mantisbt 1.0.3

mantisbt mantisbt 0.19.0

mantisbt mantisbt 0.19.4

mantisbt mantisbt 0.19.3

mantisbt mantisbt

mantisbt mantisbt 1.2.4

mantisbt mantisbt 1.2.3

mantisbt mantisbt 1.2.0

mantisbt mantisbt 1.1.1

mantisbt mantisbt 1.1.8

mantisbt mantisbt 1.1.5

mantisbt mantisbt 1.0.8

mantisbt mantisbt 1.0.5

mantisbt mantisbt 0.19.1

mantisbt mantisbt 0.19.2

mantisbt mantisbt 1.2.8

mantisbt mantisbt 1.2.7

mantisbt mantisbt 1.1.9

mantisbt mantisbt 1.1.6

mantisbt mantisbt 1.1.7

mantisbt mantisbt 1.0.2

mantisbt mantisbt 1.0.1

mantisbt mantisbt 1.0.6

mantisbt mantisbt 1.0.9

mantisbt mantisbt 0.18.0

mantisbt mantisbt 0.19.5

mantisbt mantisbt 1.2.6

mantisbt mantisbt 1.2.5

mantisbt mantisbt 1.1.4

mantisbt mantisbt 1.0.7

mantisbt mantisbt 1.0.4