Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-crqg-wcv6-jc2c

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью

Описание

MantisBT before 1.2.12 does not use an expected default value during decisions about whether a user may modify the status of a bug, which allows remote authenticated users to bypass intended access restrictions and make status changes by leveraging a blank value for a per-status setting.

MantisBT before 1.2.12 does not use an expected default value during decisions about whether a user may modify the status of a bug, which allows remote authenticated users to bypass intended access restrictions and make status changes by leveraging a blank value for a per-status setting.

EPSS

Процентиль: 39%
0.00177
Низкий

Связанные уязвимости

ubuntu
около 13 лет назад

MantisBT before 1.2.12 does not use an expected default value during decisions about whether a user may modify the status of a bug, which allows remote authenticated users to bypass intended access restrictions and make status changes by leveraging a blank value for a per-status setting.

nvd
около 13 лет назад

MantisBT before 1.2.12 does not use an expected default value during decisions about whether a user may modify the status of a bug, which allows remote authenticated users to bypass intended access restrictions and make status changes by leveraging a blank value for a per-status setting.

debian
около 13 лет назад

MantisBT before 1.2.12 does not use an expected default value during d ...

EPSS

Процентиль: 39%
0.00177
Низкий