Input validation error in MantisBT - CVE-2013-1811
Published: November 8, 2019 / Updated: July 17, 2020
Vulnerability identifier: #VU30630
CSH Severity: Low
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2013-1811
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerable software:
MantisBT
MantisBT
Software vendor:
mantisbt.sourceforge.net
mantisbt.sourceforge.net
Description
The vulnerability allows a remote authenticated user to manipulate data.
An access control issue in MantisBT before 1.2.13 allows users with "Reporter" permissions to change any issue to "New".
Remediation
Install update from vendor's website.