3.6

CVE-2012-1120

The SOAP API in MantisBT before 1.2.9 does not properly enforce the bugnote_allow_user_edit_delete and delete_bug_threshold permissions, which allows remote authenticated users with read and write SOAP API privileges to delete arbitrary bug reports and bug notes.

Data is provided by the National Vulnerability Database (NVD)
MantisbtMantisbt Version <= 1.2.8
MantisbtMantisbt Version0.18.0
MantisbtMantisbt Version0.19.0
MantisbtMantisbt Version0.19.0 Updatea1
MantisbtMantisbt Version0.19.0 Updatea2
MantisbtMantisbt Version0.19.0 Updaterc1
MantisbtMantisbt Version0.19.1
MantisbtMantisbt Version0.19.2
MantisbtMantisbt Version0.19.3
MantisbtMantisbt Version0.19.4
MantisbtMantisbt Version0.19.5
MantisbtMantisbt Version1.0.0
MantisbtMantisbt Version1.0.0 Updatea1
MantisbtMantisbt Version1.0.0 Updatea2
MantisbtMantisbt Version1.0.0 Updatea3
MantisbtMantisbt Version1.0.0 Updaterc1
MantisbtMantisbt Version1.0.0 Updaterc2
MantisbtMantisbt Version1.0.0 Updaterc3
MantisbtMantisbt Version1.0.0 Updaterc4
MantisbtMantisbt Version1.0.0 Updaterc5
MantisbtMantisbt Version1.0.1
MantisbtMantisbt Version1.0.2
MantisbtMantisbt Version1.0.3
MantisbtMantisbt Version1.0.4
MantisbtMantisbt Version1.0.5
MantisbtMantisbt Version1.0.6
MantisbtMantisbt Version1.0.7
MantisbtMantisbt Version1.0.8
MantisbtMantisbt Version1.0.9
MantisbtMantisbt Version1.1.0
MantisbtMantisbt Version1.1.0 Updatea1
MantisbtMantisbt Version1.1.0 Updatea2
MantisbtMantisbt Version1.1.0 Updatea3
MantisbtMantisbt Version1.1.0 Updatea4
MantisbtMantisbt Version1.1.0 Updaterc1
MantisbtMantisbt Version1.1.0 Updaterc2
MantisbtMantisbt Version1.1.0 Updaterc3
MantisbtMantisbt Version1.1.1
MantisbtMantisbt Version1.1.2
MantisbtMantisbt Version1.1.3
MantisbtMantisbt Version1.1.4
MantisbtMantisbt Version1.1.5
MantisbtMantisbt Version1.1.6
MantisbtMantisbt Version1.1.7
MantisbtMantisbt Version1.1.8
MantisbtMantisbt Version1.1.9
MantisbtMantisbt Version1.2.0
MantisbtMantisbt Version1.2.0 Updatealpha1
MantisbtMantisbt Version1.2.0 Updatealpha2
MantisbtMantisbt Version1.2.0 Updatealpha3
MantisbtMantisbt Version1.2.0 Updaterc1
MantisbtMantisbt Version1.2.0 Updaterc2
MantisbtMantisbt Version1.2.1
MantisbtMantisbt Version1.2.2
MantisbtMantisbt Version1.2.3
MantisbtMantisbt Version1.2.4
MantisbtMantisbt Version1.2.5
MantisbtMantisbt Version1.2.6
MantisbtMantisbt Version1.2.7
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.9% 0.735
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 3.6 3.9 4.9
AV:N/AC:H/Au:S/C:N/I:P/A:P