CVE-2013-1811
published 2019-11-07CVE-2013-1811: An access control issue in MantisBT before 1.2.13 allows users with "Reporter" permissions to change any issue to "New".
PriorityP419medium4.3CVSS 3.1
AVNACLPRLUINSUCNILAN
EPSS
1.03%
60.3th percentile
An access control issue in MantisBT before 1.2.13 allows users with "Reporter" permissions to change any issue to "New".
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| mantis | mantis | — | — |
| mantisbt | mantisbt | < 1.2.13 | 1.2.13 |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.debian.org/security/2015/dsa-3120http://www.openwall.com/lists/oss-security/2013/03/03/6http://www.openwall.com/lists/oss-security/2013/03/04/9https://mantisbt.org/bugs/view.php?id=15258https://security-tracker.debian.org/tracker/CVE-2013-1811http://www.debian.org/security/2015/dsa-3120http://www.openwall.com/lists/oss-security/2013/03/03/6http://www.openwall.com/lists/oss-security/2013/03/04/9https://mantisbt.org/bugs/view.php?id=15258https://security-tracker.debian.org/tracker/CVE-2013-1811
2019-11-07
Published