#VU30630 Input validation error in MantisBT - CVE-2013-1811


| Updated: 2020-07-17

Vulnerability identifier: #VU30630

Vulnerability risk: Low

CVSSv4.0: 1.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2013-1811

CWE-ID: CWE-20

Exploitation vector: Network

Exploit availability: No

Vulnerable software:
MantisBT
Web applications / Other software

Vendor: mantisbt.sourceforge.net

Description

The vulnerability allows a remote authenticated user to manipulate data.

An access control issue in MantisBT before 1.2.13 allows users with "Reporter" permissions to change any issue to "New".

Mitigation
Install update from vendor's website.

Vulnerable software versions

MantisBT: 1.2.0 rc1 - 1.2.12


External links
https://www.debian.org/security/2015/dsa-3120
https://www.openwall.com/lists/oss-security/2013/03/03/6
https://www.openwall.com/lists/oss-security/2013/03/04/9
https://mantisbt.org/bugs/view.php?id=15258
https://security-tracker.debian.org/tracker/CVE-2013-1811


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability