MantisBT before 1.2.11 does not check the delete_attachments_threshold permission when...
Vulnerability Description
MantisBT before 1.2.11 does not check the delete_attachments_threshold permission when form_security_validation is set to OFF, which allows remote authenticated users with certain privileges to bypass intended access restrictions and delete arbitrary attachments.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2012-2692
Credits & Attribution
No credits recorded in the NVD database.
References
- http://lists.fedoraproject.org/pipermail/package-announce/2012-November/093063.html
- http://www.securityfocus.com/bid/53921
- http://www.mantisbt.org/bugs/view.php?id=14016
- http://security.gentoo.org/glsa/glsa-201211-01.xml
- http://www.openwall.com/lists/oss-security/2012/06/11/6
- http://www.mantisbt.org/bugs/changelog_page.php?version_id=148
- http://secunia.com/advisories/51199
- http://lists.fedoraproject.org/pipermail/package-announce/2012-November/093064.html
- http://www.openwall.com/lists/oss-security/2012/06/09/1
- http://lists.fedoraproject.org/pipermail/package-announce/2012-November/092926.html
- https://github.com/mantisbt/mantisbt/commit/ceafe6f0c679411b81368052633a63dd3ca06d9c
More from mantisbt
View All →Affected Vendor
mantisbt
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.