Search Results (124 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2012-1122 1 Mantisbt 1 Mantisbt 2024-08-06 N/A
bug_actiongroup.php in MantisBT before 1.2.9 does not properly check the report_bug_threshold permission of the receiving project when moving a bug report, which allows remote authenticated users with the report_bug_threshold and move_bug_threshold privileges for a project to bypass intended access restrictions and move bug reports to a different project.
CVE-2012-1119 1 Mantisbt 1 Mantisbt 2024-08-06 N/A
MantisBT before 1.2.9 does not audit when users copy or clone a bug report, which makes it easier for remote attackers to copy bug reports without detection.
CVE-2012-1123 1 Mantisbt 1 Mantisbt 2024-08-06 N/A
The mci_check_login function in api/soap/mc_api.php in the SOAP API in MantisBT before 1.2.9 allows remote attackers to bypass authentication via a null password.
CVE-2013-4460 1 Mantisbt 1 Mantisbt 2024-08-06 N/A
Cross-site scripting (XSS) vulnerability in account_sponsor_page.php in MantisBT 1.0.0 through 1.2.15 allows remote authenticated users to inject arbitrary web script or HTML via a project name.