Input validation error in MantisBT - CVE-2013-1811

 

Input validation error in MantisBT - CVE-2013-1811

Published: November 8, 2019 / Updated: July 17, 2020


Vulnerability identifier: #VU30630
CSH Severity: Low
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2013-1811
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
MantisBT
Software vendor:
mantisbt.sourceforge.net

Description

The vulnerability allows a remote authenticated user to manipulate data.

An access control issue in MantisBT before 1.2.13 allows users with "Reporter" permissions to change any issue to "New".


Remediation

Install update from vendor's website.

External links