MantisBT: REST API unauthorized Issue status change
A MantisBT user having $g_update_bug_threshold (UPDATER by default) can change an Issue's Status via REST and SOAP API, even if the $g_set_status_threshold config is set to a higher level (DEVELOPER by default).
Unauthorized change in Issue workflow.
https://github.com/mantisbt/mantisbt/releases/tag/release-2.28.4
None
Mamdouh Mahfouz (@mamdouhmahfouz)
Why this VPI (explainable, experimental)
VPI breakdown
| Impact(default (no data)) | 55.00 |
| Exploitation signal(No additional exploitation signal) | ×1.00 |
| VPI | 55.00 |
VPI formula vpi-v1