An access control issue in MantisBT before 1.2.13

Overview :
An access control issue in MantisBT before 1.2.13 allows users with “Reporter” permissions to change any issue to “New”.
Affected Product(s) :
  • MantisBT 1.2.12
Vulnerability Details :
CVE ID : CVE-2013-1811
Damien Regad (MantisBT developer) discovered and fixed an access control/permissions bug in MantisBT that exists in MantisBT version 1.2.12 and prior.
A MantisBT user with “Reporter” permissions (enabling them to report/create new issues) can modify the workflow status of any issue to
“New” even if they do not have the necessary permission to make this change.

Details of the bug, including steps to reproduce and patches are available at .
References:
>> http://www.mantisbt.org/bugs/view.php?id=15258

Solution :

Update to MantisBT version 1.2.13.

 

Common Vulnerabilityies and Exposures

Contact us to get started

CVE-2022-1840 : Home Clean Services Management System Stored Cross-Site Scripting (XSS)

CVE-2022-1840 : Home Clean Services Management System Stored Cross-Site Scripting (XSS)

Description Persistent XSS (or Stored XSS) attack is one of the three major categories of XSS attacks, the others being

CVE-2022-1558 : Multiple Stored Cross-Site Scripting vulnerabilities in WordPress curtain plugin 1.0.2

CVE-2022-1558 : Multiple Stored Cross-Site Scripting vulnerabilities in WordPress curtain plugin 1.0.2

Description Several Cross-Site Scripting vulnerabilities in the Curtain WordPress plugin. Due to these Cross-Site Scripting vulnerabilities, an attacker would be

CVE-2022-AVAST2 : Self-Defense Bypass via Repairing Function

CVE-2022-AVAST2 : Self-Defense Bypass via Repairing Function

Description It was noted that there is security checking to prevent some of the Avast processes from loading of undesired/unsigned