View Issue Details

IDProjectCategoryView StatusLast Update
0016737mantisbtauthenticationpublic2014-01-03 05:56
Reporterporush mittal Assigned Todregad  
PriorityurgentSeveritytrivialReproducibilityalways
Status closedResolutionno change required 
PlatformWindowsOSXP 
Product Version1.2.12 
Summary0016737: Reporter is able to modify the status of any public issue to new issue
Description

Reporter is able to modify the status of any public issue to new issue . Reporter should only be able to reopen his/her issue via reopen tab.

But he is able to change the resolve status to new status for the calls which is not logged via him.

TagsNo tags attached.
Attached Files
Issue_With_Reporter_role.png (227,659 bytes)   
Issue_With_Reporter_role.png (227,659 bytes)   

Relationships

duplicate of 0015258 closeddregad CVE-2013-1811 Reporter can change issue status to 'new' 

Activities

atrol

atrol

2013-12-20 08:48

developer   ~0038906

Last edited: 2013-12-20 08:48

This is not reproducible with latest stable version of MantisBT (1.2.15 at the moment) and the standard configuration.

a) Check your configuration (Workflow Thresholds)
b) Update to 1.2.15

dregad

dregad

2013-12-20 11:08

developer   ~0038907

This was fixed in 1.2.13. As mentioned by atrol, please upgrade to the latest version.

porush mittal

porush mittal

2013-12-21 00:27

reporter   ~0038909

Dear Team ,

If we update the version will this keep the older configuration ... like custom fields etc .

porush mittal

porush mittal

2013-12-21 00:35

reporter   ~0038910

If

atrol

atrol

2013-12-21 03:41

developer   ~0038911

You will not lose anything if you follow the upgrade instructions.
http://www.mantisbt.org/docs/master-1.2.x/en/administration_guide.html#ADMIN.INSTALL.PREINSTALL