Loading...
Loading...
The access_has_bug_level function in core/access_api.php in MantisBT before 1.2.9 does not properly restrict access when the private_bug_view_threshold is set to an array, which allows remote attackers to bypass intended restrictions and perform certain operations on private bug reports.
June 29, 2012
April 29, 2026
See which npm, PyPI, Go, and Maven packages are affected by CVE-2012-1118
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.