Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xphv-v337-3g8j

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью

Описание

MantisBT before 1.2.11 does not check the delete_attachments_threshold permission when form_security_validation is set to OFF, which allows remote authenticated users with certain privileges to bypass intended access restrictions and delete arbitrary attachments.

MantisBT before 1.2.11 does not check the delete_attachments_threshold permission when form_security_validation is set to OFF, which allows remote authenticated users with certain privileges to bypass intended access restrictions and delete arbitrary attachments.

EPSS

Процентиль: 71%
0.0066
Низкий

Связанные уязвимости

ubuntu
больше 13 лет назад

MantisBT before 1.2.11 does not check the delete_attachments_threshold permission when form_security_validation is set to OFF, which allows remote authenticated users with certain privileges to bypass intended access restrictions and delete arbitrary attachments.

nvd
больше 13 лет назад

MantisBT before 1.2.11 does not check the delete_attachments_threshold permission when form_security_validation is set to OFF, which allows remote authenticated users with certain privileges to bypass intended access restrictions and delete arbitrary attachments.

debian
больше 13 лет назад

MantisBT before 1.2.11 does not check the delete_attachments_threshold ...

EPSS

Процентиль: 71%
0.0066
Низкий