Arbitrary Bugnote Editing Vulnerability in MantisBT SOAP API
CVE-2012-2691 · HIGH Severity
AV:N/AC:L/AU:N/C:P/I:P/A:P
The mc_issue_note_update function in the SOAP API in MantisBT before 1.2.11 does not properly check privileges, which allows remote attackers with bug reporting privileges to edit arbitrary bugnotes via a SOAP request.
Learn more about our Api Penetration Testing.