||Damien Regad (MantisBT developer) discovered and fixed an access control/permissions bug in MantisBT that exists in MantisBT version 1.2.12 and prior.
A MantisBT user with “Reporter” permissions (enabling them to report/create new issues) can modify the workflow status of any issue to
“New” even if they do not have the necessary permission to make this change.
Details of the bug, including steps to reproduce and patches are available at .
>>  http://www.mantisbt.org/bugs/view.php?id=15258