An access control issue in MantisBT before 1.2.13 allows users with "Reporter" permissions to change any issue to "New".
https://security-tracker.debian.org/tracker/CVE-2013-1811
https://mantisbt.org/bugs/view.php?id=15258
http://www.openwall.com/lists/oss-security/2013/03/04/9