CVE-2012-1121: Mantisbt

Medium severity, CVSS 4.9. EPSS: 2.2% chance of exploitation in the next 30 days.

MantisBT before 1.2.9 does not properly check permissions, which allows remote authenticated users with manager privileges to (1) modify or (2) delete global categories.

Affected products

  • Mantisbt Mantisbt: up to and including 1.2.8; version 0.18.0 only; version 0.19.0 only; version 0.19.1 only; version 0.19.2 only; version 0.19.3 only; …

Published 2012-06-29. Last modified 2026-06-16.