Beveiligingsadvies

CVE-2012-2691

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2012-06-17 01:00:00
Laatst bijgewerkt 2024-08-06 19:42:32
Toegewezen door redhat
CVSS-score geen score
Status PUBLISHED

Beschrijving

The mc_issue_note_update function in the SOAP API in MantisBT before 1.2.11 does not properly check privileges, which allows remote attackers with bug reporting privileges to edit arbitrary bugnotes via a SOAP request.