MantisBT contains a flaw that is triggered when copying or cloning a bug using the "View Issues" page. This will result in the bug failing to leave an audit trail. While such an issue may be minor, it may violate company security policy.
Classification
Location:
Remote / Network Access
Attack Type:
Other
Impact:
Loss of Integrity
Solution:
Upgrade
Exploit:
Exploit Public
Disclosure:
Third-party Verified
OSVDB:
Authentication Required
Solution
Upgrade to version 1.2.9 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.