Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2012-5522

Опубликовано: 16 нояб. 2012
Источник: debian
EPSS Низкий

Описание

MantisBT before 1.2.12 does not use an expected default value during decisions about whether a user may modify the status of a bug, which allows remote authenticated users to bypass intended access restrictions and make status changes by leveraging a blank value for a per-status setting.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
mantisfixed1.2.11-1.2package
mantisend-of-lifesqueezepackage

Примечания

  • http://www.mantisbt.org/bugs/view.php?id=14496

EPSS

Процентиль: 39%
0.00177
Низкий

Связанные уязвимости

ubuntu
около 13 лет назад

MantisBT before 1.2.12 does not use an expected default value during decisions about whether a user may modify the status of a bug, which allows remote authenticated users to bypass intended access restrictions and make status changes by leveraging a blank value for a per-status setting.

nvd
около 13 лет назад

MantisBT before 1.2.12 does not use an expected default value during decisions about whether a user may modify the status of a bug, which allows remote authenticated users to bypass intended access restrictions and make status changes by leveraging a blank value for a per-status setting.

github
больше 3 лет назад

MantisBT before 1.2.12 does not use an expected default value during decisions about whether a user may modify the status of a bug, which allows remote authenticated users to bypass intended access restrictions and make status changes by leveraging a blank value for a per-status setting.

EPSS

Процентиль: 39%
0.00177
Низкий