An access control issue in MantisBT before 1.2.13 allows users with "Reporter" permissions to change any issue to "New".
https://security-tracker.debian.org/tracker/CVE-2013-1811
http://www.openwall.com/lists/oss-security/2013/03/04/9
http://www.openwall.com/lists/oss-security/2013/03/03/6
http://www.debian.org/security/2015/dsa-3120
https://mantisbt.org/bugs/view.php?id=15258
Source: Mitre, NVD
Published: 2019-11-07
Updated: 2019-11-09
Base Score: 4
Vector: CVSS2#AV:N/AC:L/Au:S/C:N/I:P/A:N
Severity: Medium
Base Score: 4.3
Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
EPSS: 0.00325