CVE-2012-2692
Last modified
CVE-2012-2692 is a vulnerability of currently unknown severity. MantisBT before 1.2.11 does not check the delete_attachments_threshold permission when form_security_validation is set to OFF, which allows remote authenticated users with certain privileges to bypass intended access restrictions and delete arbitrary attachments.. EPSS estimates a 1.46% chance of exploitation in the next 30 days.
Description
MantisBT before 1.2.11 does not check the delete_attachments_threshold permission when form_security_validation is set to OFF, which allows remote authenticated users with certain privileges to bypass intended access restrictions and delete arbitrary attachments.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mantisbt | Mantisbt | <= 1.2.10 |
| Mantisbt | Mantisbt | 0.18.0 |
| Mantisbt | Mantisbt | 0.19.0 |
| Mantisbt | Mantisbt | 0.19.1 |
| Mantisbt | Mantisbt | 0.19.2 |
| Mantisbt | Mantisbt | 0.19.3 |
| Mantisbt | Mantisbt | 0.19.4 |
| Mantisbt | Mantisbt | 0.19.5 |
| Mantisbt | Mantisbt | 1.0.0 |
| Mantisbt | Mantisbt | 1.0.1 |
| Mantisbt | Mantisbt | 1.0.2 |
| Mantisbt | Mantisbt | 1.0.3 |
| Mantisbt | Mantisbt | 1.0.4 |
| Mantisbt | Mantisbt | 1.0.5 |
| Mantisbt | Mantisbt | 1.0.6 |
| Mantisbt | Mantisbt | 1.0.7 |
| Mantisbt | Mantisbt | 1.0.8 |
| Mantisbt | Mantisbt | 1.1.0 |
| Mantisbt | Mantisbt | 1.1.1 |
| Mantisbt | Mantisbt | 1.1.2 |
| Mantisbt | Mantisbt | 1.1.4 |
| Mantisbt | Mantisbt | 1.1.5 |
| Mantisbt | Mantisbt | 1.1.6 |
| Mantisbt | Mantisbt | 1.1.7 |
| Mantisbt | Mantisbt | 1.1.8 |
| Mantisbt | Mantisbt | 1.2.0 |
| Mantisbt | Mantisbt | 1.2.1 |
| Mantisbt | Mantisbt | 1.2.2 |
| Mantisbt | Mantisbt | 1.2.3 |
| Mantisbt | Mantisbt | 1.2.4 |
| Mantisbt | Mantisbt | 1.2.5 |
| Mantisbt | Mantisbt | 1.2.6 |
| Mantisbt | Mantisbt | 1.2.7 |
| Mantisbt | Mantisbt | 1.2.8 |
| Mantisbt | Mantisbt | 1.2.9 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2012-2692?
How severe is CVE-2012-2692?
How do I fix CVE-2012-2692?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2012
- CVE-2012-2686crypto/evp/e_aes_cbc_hmac_sha1.c in the AES-NI functionality…
- CVE-2012-2687Multiple cross-site scripting (XSS) vulnerabilities in the m…
- CVE-2012-2688Unspecified vulnerability in the _php_stream_scandir functio…
- CVE-2012-2689Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2012-2690virt-edit in libguestfs before 1.18.0 does not preserve the …
- CVE-2012-2691The mc_issue_note_update function in the SOAP API in MantisB…
- CVE-2012-2693libvirt, possibly before 0.9.12, does not properly assign US…
- CVE-2012-2694actionpack/lib/action_dispatch/http/request.rb in Ruby on Ra…
- CVE-2012-2695The Active Record component in Ruby on Rails before 3.0.14, …
- CVE-2012-2696The backend in Red Hat Enterprise Virtualization Manager (RH…
- CVE-2012-2697Unspecified vulnerability in autofs, as used in Red Hat Ente…
- CVE-2012-2698Cross-site scripting (XSS) vulnerability in the outputPage f…
Are you affected by CVE-2012-2692?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
