mailing list archives
CVE request: MantisBT before 1.2.13 "Change Status To" feature allows unauthorised workflow changes
From: David Hicks <d () hx id au>
Date: Sat, 19 Jan 2013 11:35:06 +1100
Hello again list,
Damien Regad (MantisBT developer) discovered and fixed an access
control/permissions bug in MantisBT that exists in MantisBT version
1.2.12 and prior.
A MantisBT user with "Reporter" permissions (enabling them to
report/create new issues) can modify the workflow status of any issue to
"New" even if they do not have the necessary permission to make this
Details of the bug, including steps to reproduce and patches are
available at .
As per previous e-mails to this list within the past 24 hours, MantisBT
1.2.13 is expected to be released early next week.
Can a CVE ID please be assigned to this issue?
Bcc: mantisbt-dev () lists sourceforge net
Description: This is a digitally signed message part
- CVE request: MantisBT before 1.2.13 "Change Status To" feature allows unauthorised workflow changes David Hicks (Jan 19)