Arbitrary Bugnote Editing Vulnerability in MantisBT SOAP API

Arbitrary Bugnote Editing Vulnerability in MantisBT SOAP API

CVE-2012-2691 · HIGH Severity

AV:N/AC:L/AU:N/C:P/I:P/A:P

The mc_issue_note_update function in the SOAP API in MantisBT before 1.2.11 does not properly check privileges, which allows remote attackers with bug reporting privileges to edit arbitrary bugnotes via a SOAP request.

Learn more about our Api Penetration Testing.