// For flags

CVE-2012-1122

 

Severity Score

3.6
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

bug_actiongroup.php in MantisBT before 1.2.9 does not properly check the report_bug_threshold permission of the receiving project when moving a bug report, which allows remote authenticated users with the report_bug_threshold and move_bug_threshold privileges for a project to bypass intended access restrictions and move bug reports to a different project.

bug_actiongroup.php de MantisBT anteriores a 1.2.9 no comprueba apropiadamente el permiso report_bug_threshold del proyecto destino cuando se mueve un reporte de bug, lo que permite a usuarios autenticados remotos con los privilegios report_bug_threshold y move_bug_threshold para un proyecto evitar las restricciones de acceso previstas y mover reportes de bug a un proyecto distinto.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
High
Authentication
Single
Confidentiality
None
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2012-02-14 CVE Reserved
  • 2012-06-24 CVE Published
  • 2023-11-25 EPSS Updated
  • 2024-08-06 CVE Updated
  • 2024-08-06 First Exploit
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-264: Permissions, Privileges, and Access Controls
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Mantisbt
Search vendor "Mantisbt"
Mantisbt
Search vendor "Mantisbt" for product "Mantisbt"
<= 1.2.8
Search vendor "Mantisbt" for product "Mantisbt" and version " <= 1.2.8"
-
Affected
Mantisbt
Search vendor "Mantisbt"
Mantisbt
Search vendor "Mantisbt" for product "Mantisbt"
0.18.0
Search vendor "Mantisbt" for product "Mantisbt" and version "0.18.0"
-
Affected
Mantisbt
Search vendor "Mantisbt"
Mantisbt
Search vendor "Mantisbt" for product "Mantisbt"
0.19.0
Search vendor "Mantisbt" for product "Mantisbt" and version "0.19.0"
-
Affected
Mantisbt
Search vendor "Mantisbt"
Mantisbt
Search vendor "Mantisbt" for product "Mantisbt"
0.19.0
Search vendor "Mantisbt" for product "Mantisbt" and version "0.19.0"
rc1
Affected
Mantisbt
Search vendor "Mantisbt"
Mantisbt
Search vendor "Mantisbt" for product "Mantisbt"
0.19.0a1
Search vendor "Mantisbt" for product "Mantisbt" and version "0.19.0a1"
-
Affected
Mantisbt
Search vendor "Mantisbt"
Mantisbt
Search vendor "Mantisbt" for product "Mantisbt"
0.19.0a2
Search vendor "Mantisbt" for product "Mantisbt" and version "0.19.0a2"
-
Affected
Mantisbt
Search vendor "Mantisbt"
Mantisbt
Search vendor "Mantisbt" for product "Mantisbt"
0.19.1
Search vendor "Mantisbt" for product "Mantisbt" and version "0.19.1"
-
Affected
Mantisbt
Search vendor "Mantisbt"
Mantisbt
Search vendor "Mantisbt" for product "Mantisbt"
0.19.2
Search vendor "Mantisbt" for product "Mantisbt" and version "0.19.2"
-
Affected
Mantisbt
Search vendor "Mantisbt"
Mantisbt
Search vendor "Mantisbt" for product "Mantisbt"
0.19.3
Search vendor "Mantisbt" for product "Mantisbt" and version "0.19.3"
-
Affected
Mantisbt
Search vendor "Mantisbt"
Mantisbt
Search vendor "Mantisbt" for product "Mantisbt"
0.19.4
Search vendor "Mantisbt" for product "Mantisbt" and version "0.19.4"
-
Affected
Mantisbt
Search vendor "Mantisbt"
Mantisbt
Search vendor "Mantisbt" for product "Mantisbt"
0.19.5
Search vendor "Mantisbt" for product "Mantisbt" and version "0.19.5"
-
Affected
Mantisbt
Search vendor "Mantisbt"
Mantisbt
Search vendor "Mantisbt" for product "Mantisbt"
1.0.0
Search vendor "Mantisbt" for product "Mantisbt" and version "1.0.0"
-
Affected
Mantisbt
Search vendor "Mantisbt"
Mantisbt
Search vendor "Mantisbt" for product "Mantisbt"
1.0.0
Search vendor "Mantisbt" for product "Mantisbt" and version "1.0.0"
rc1
Affected
Mantisbt
Search vendor "Mantisbt"
Mantisbt
Search vendor "Mantisbt" for product "Mantisbt"
1.0.0
Search vendor "Mantisbt" for product "Mantisbt" and version "1.0.0"
rc2
Affected
Mantisbt
Search vendor "Mantisbt"
Mantisbt
Search vendor "Mantisbt" for product "Mantisbt"
1.0.0
Search vendor "Mantisbt" for product "Mantisbt" and version "1.0.0"
rc3
Affected
Mantisbt
Search vendor "Mantisbt"
Mantisbt
Search vendor "Mantisbt" for product "Mantisbt"
1.0.0
Search vendor "Mantisbt" for product "Mantisbt" and version "1.0.0"
rc4
Affected
Mantisbt
Search vendor "Mantisbt"
Mantisbt
Search vendor "Mantisbt" for product "Mantisbt"
1.0.0
Search vendor "Mantisbt" for product "Mantisbt" and version "1.0.0"
rc5
Affected
Mantisbt
Search vendor "Mantisbt"
Mantisbt
Search vendor "Mantisbt" for product "Mantisbt"
1.0.0a1
Search vendor "Mantisbt" for product "Mantisbt" and version "1.0.0a1"
-
Affected
Mantisbt
Search vendor "Mantisbt"
Mantisbt
Search vendor "Mantisbt" for product "Mantisbt"
1.0.0a2
Search vendor "Mantisbt" for product "Mantisbt" and version "1.0.0a2"
-
Affected
Mantisbt
Search vendor "Mantisbt"
Mantisbt
Search vendor "Mantisbt" for product "Mantisbt"
1.0.0a3
Search vendor "Mantisbt" for product "Mantisbt" and version "1.0.0a3"
-
Affected
Mantisbt
Search vendor "Mantisbt"
Mantisbt
Search vendor "Mantisbt" for product "Mantisbt"
1.0.1
Search vendor "Mantisbt" for product "Mantisbt" and version "1.0.1"
-
Affected
Mantisbt
Search vendor "Mantisbt"
Mantisbt
Search vendor "Mantisbt" for product "Mantisbt"
1.0.2
Search vendor "Mantisbt" for product "Mantisbt" and version "1.0.2"
-
Affected
Mantisbt
Search vendor "Mantisbt"
Mantisbt
Search vendor "Mantisbt" for product "Mantisbt"
1.0.3
Search vendor "Mantisbt" for product "Mantisbt" and version "1.0.3"
-
Affected
Mantisbt
Search vendor "Mantisbt"
Mantisbt
Search vendor "Mantisbt" for product "Mantisbt"
1.0.4
Search vendor "Mantisbt" for product "Mantisbt" and version "1.0.4"
-
Affected
Mantisbt
Search vendor "Mantisbt"
Mantisbt
Search vendor "Mantisbt" for product "Mantisbt"
1.0.5
Search vendor "Mantisbt" for product "Mantisbt" and version "1.0.5"
-
Affected
Mantisbt
Search vendor "Mantisbt"
Mantisbt
Search vendor "Mantisbt" for product "Mantisbt"
1.0.6
Search vendor "Mantisbt" for product "Mantisbt" and version "1.0.6"
-
Affected
Mantisbt
Search vendor "Mantisbt"
Mantisbt
Search vendor "Mantisbt" for product "Mantisbt"
1.0.7
Search vendor "Mantisbt" for product "Mantisbt" and version "1.0.7"
-
Affected
Mantisbt
Search vendor "Mantisbt"
Mantisbt
Search vendor "Mantisbt" for product "Mantisbt"
1.0.8
Search vendor "Mantisbt" for product "Mantisbt" and version "1.0.8"
-
Affected
Mantisbt
Search vendor "Mantisbt"
Mantisbt
Search vendor "Mantisbt" for product "Mantisbt"
1.1.0
Search vendor "Mantisbt" for product "Mantisbt" and version "1.1.0"
-
Affected
Mantisbt
Search vendor "Mantisbt"
Mantisbt
Search vendor "Mantisbt" for product "Mantisbt"
1.1.1
Search vendor "Mantisbt" for product "Mantisbt" and version "1.1.1"
-
Affected
Mantisbt
Search vendor "Mantisbt"
Mantisbt
Search vendor "Mantisbt" for product "Mantisbt"
1.1.2
Search vendor "Mantisbt" for product "Mantisbt" and version "1.1.2"
-
Affected
Mantisbt
Search vendor "Mantisbt"
Mantisbt
Search vendor "Mantisbt" for product "Mantisbt"
1.1.4
Search vendor "Mantisbt" for product "Mantisbt" and version "1.1.4"
-
Affected
Mantisbt
Search vendor "Mantisbt"
Mantisbt
Search vendor "Mantisbt" for product "Mantisbt"
1.1.5
Search vendor "Mantisbt" for product "Mantisbt" and version "1.1.5"
-
Affected
Mantisbt
Search vendor "Mantisbt"
Mantisbt
Search vendor "Mantisbt" for product "Mantisbt"
1.1.6
Search vendor "Mantisbt" for product "Mantisbt" and version "1.1.6"
-
Affected
Mantisbt
Search vendor "Mantisbt"
Mantisbt
Search vendor "Mantisbt" for product "Mantisbt"
1.1.7
Search vendor "Mantisbt" for product "Mantisbt" and version "1.1.7"
-
Affected
Mantisbt
Search vendor "Mantisbt"
Mantisbt
Search vendor "Mantisbt" for product "Mantisbt"
1.1.8
Search vendor "Mantisbt" for product "Mantisbt" and version "1.1.8"
-
Affected
Mantisbt
Search vendor "Mantisbt"
Mantisbt
Search vendor "Mantisbt" for product "Mantisbt"
1.2.0
Search vendor "Mantisbt" for product "Mantisbt" and version "1.2.0"
-
Affected
Mantisbt
Search vendor "Mantisbt"
Mantisbt
Search vendor "Mantisbt" for product "Mantisbt"
1.2.0a1
Search vendor "Mantisbt" for product "Mantisbt" and version "1.2.0a1"
-
Affected
Mantisbt
Search vendor "Mantisbt"
Mantisbt
Search vendor "Mantisbt" for product "Mantisbt"
1.2.0a2
Search vendor "Mantisbt" for product "Mantisbt" and version "1.2.0a2"
-
Affected
Mantisbt
Search vendor "Mantisbt"
Mantisbt
Search vendor "Mantisbt" for product "Mantisbt"
1.2.1
Search vendor "Mantisbt" for product "Mantisbt" and version "1.2.1"
-
Affected
Mantisbt
Search vendor "Mantisbt"
Mantisbt
Search vendor "Mantisbt" for product "Mantisbt"
1.2.2
Search vendor "Mantisbt" for product "Mantisbt" and version "1.2.2"
-
Affected
Mantisbt
Search vendor "Mantisbt"
Mantisbt
Search vendor "Mantisbt" for product "Mantisbt"
1.2.3
Search vendor "Mantisbt" for product "Mantisbt" and version "1.2.3"
-
Affected
Mantisbt
Search vendor "Mantisbt"
Mantisbt
Search vendor "Mantisbt" for product "Mantisbt"
1.2.4
Search vendor "Mantisbt" for product "Mantisbt" and version "1.2.4"
-
Affected
Mantisbt
Search vendor "Mantisbt"
Mantisbt
Search vendor "Mantisbt" for product "Mantisbt"
1.2.5
Search vendor "Mantisbt" for product "Mantisbt" and version "1.2.5"
-
Affected
Mantisbt
Search vendor "Mantisbt"
Mantisbt
Search vendor "Mantisbt" for product "Mantisbt"
1.2.6
Search vendor "Mantisbt" for product "Mantisbt" and version "1.2.6"
-
Affected
Mantisbt
Search vendor "Mantisbt"
Mantisbt
Search vendor "Mantisbt" for product "Mantisbt"
1.2.7
Search vendor "Mantisbt" for product "Mantisbt" and version "1.2.7"
-
Affected