CVSS2
Attack Vector
NETWORK
Attack Complexity
HIGH
Authentication
SINGLE
Confidentiality Impact
NONE
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:N/AC:H/Au:S/C:N/I:P/A:P
EPSS
Percentile
71.8%
MantisBT before 1.2.11 does not check the delete_attachments_threshold
permission when form_security_validation is set to OFF, which allows remote
authenticated users with certain privileges to bypass intended access
restrictions and delete arbitrary attachments.
www.mantisbt.org/bugs/changelog_page.php?version_id=148
www.mantisbt.org/bugs/view.php?id=14016
www.openwall.com/lists/oss-security/2012/06/09/1
www.openwall.com/lists/oss-security/2012/06/11/6
github.com/mantisbt/mantisbt/commit/ceafe6f0c679411b81368052633a63dd3ca06d9c
launchpad.net/bugs/cve/CVE-2012-2692
nvd.nist.gov/vuln/detail/CVE-2012-2692
security-tracker.debian.org/tracker/CVE-2012-2692
www.cve.org/CVERecord?id=CVE-2012-2692