← Back

CVE-2012-5522

nvd nist
Published: Nov 16, 2012Modified: Apr 29, 2026

JSON object

Loading...
5.5
Vector
AV:N/AC:L/Au:S/C:P/I:P/A:N
Exploitability: 8.0 / Impact: 4.9
Source: NVD

Description

MantisBT before 1.2.12 does not use an expected default value during decisions about whether a user may modify the status of a bug, which allows remote authenticated users to bypass intended access restrictions and make status changes by leveraging a blank value for a per-status setting.

Affected (62)

Products: Mantisbt: Mantisbt
1 product
Mantisbt
Configuration A
62 vulnerable
Vulnerable SoftwareAffected Versions
Mantisbt
Up to 1.2.11
Version 0.18.0
Version 0.19.0
Version 0.19.0 a1
Version 0.19.0 a2
Version 0.19.0 rc1
Version 0.19.1
Version 0.19.2
Version 0.19.3
Version 0.19.4
Version 0.19.5
Version 1.0.0
Version 1.0.0 a1
Version 1.0.0 a2
Version 1.0.0 a3
Version 1.0.0 rc1
Version 1.0.0 rc2
Version 1.0.0 rc3
Version 1.0.0 rc4
Version 1.0.0 rc5
Version 1.0.1
Version 1.0.2
Version 1.0.3
Version 1.0.4
Version 1.0.5
Version 1.0.6
Version 1.0.7
Version 1.0.8
Version 1.0.9
Version 1.1.0
Version 1.1.0 a1
Version 1.1.0 a2
Version 1.1.0 a3
Version 1.1.0 a4
Version 1.1.0 rc1
Version 1.1.0 rc2
Version 1.1.0 rc3
Version 1.1.1
Version 1.1.2
Version 1.1.3
Version 1.1.4
Version 1.1.5
Version 1.1.6
Version 1.1.7
Version 1.1.8
Version 1.1.9
Version 1.2.0
Version 1.2.0 alpha1
Version 1.2.0 alpha2
Version 1.2.0 alpha3
Version 1.2.0 rc1
Version 1.2.0 rc2
Version 1.2.10
Version 1.2.1
Version 1.2.2
Version 1.2.3
Version 1.2.4
Version 1.2.5
Version 1.2.6
Version 1.2.7
Version 1.2.8
Version 1.2.9

Related CWEs

Timeline

No history available yet.