MantisBT contains a flaw related to the SOAP API. This issue is triggered when the mc_issue_note_update function uses the option $g_add_bugnote_threshold, which will default to REPORTER. This may allow an attacker to remove the contents of arbitrary bug notes.
Classification
Location:
Remote / Network Access
Attack Type:
Input Manipulation
Impact:
Loss of Integrity
Solution:
Upgrade
Exploit:
Exploit Public
Disclosure:
Vendor Verified
Solution
Upgrade to version 1.2.11 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.