Input validation error in MantisBT - CVE-2013-1811
Published: November 8, 2019 / Updated: July 17, 2020
Vulnerability identifier: #VU30630
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2013-1811
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote authenticated user to manipulate data.
An access control issue in MantisBT before 1.2.13 allows users with "Reporter" permissions to change any issue to "New".
Affected software
MantisBT
How to mitigate CVE-2013-1811
Install update from vendor's website.
MantisBT - update to 1.2.13