CVE-2012-1122
Publication date 29 June 2012
Last updated 24 July 2024
Ubuntu priority
Description
bug_actiongroup.php in MantisBT before 1.2.9 does not properly check the report_bug_threshold permission of the receiving project when moving a bug report, which allows remote authenticated users with the report_bug_threshold and move_bug_threshold privileges for a project to bypass intended access restrictions and move bug reports to a different project.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| mantis | ||