Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2012-2692

MantisBT before 1.2.11 does not check the delete_attachments_threshold permission when form_security_validation is set to OFF, which allows remote authenticated users with certain privileges to bypass intended access restrictions and delete arbitrary attachments.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.007
EPSS Ranking 70.2%
CVSS Severity
CVSS v2 Score 3.6
References
Products affected by CVE-2012-2692


Contact Us

Shodan ® - All rights reserved