Input validation error in MantisBT - CVE-2013-1811

 

Input validation error in MantisBT - CVE-2013-1811

Published: November 8, 2019 / Updated: July 17, 2020


Vulnerability identifier: #VU30630
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2013-1811
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote authenticated user to manipulate data.

An access control issue in MantisBT before 1.2.13 allows users with "Reporter" permissions to change any issue to "New".


Affected software

MantisBT

How to mitigate CVE-2013-1811

Install update from vendor's website.

MantisBT - update to 1.2.13

External References

Related Security Bulletins