CVE-2014-962412.09.2017, 14:29CAPTCHA bypass vulnerability in MantisBT before 1.2.19.EnginsightProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVectorNISTNIST7.5 HIGHNETWORKLOWNONECVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:NmitreCNA------CVEADP------Base ScoreCVSS 3.xEPSS ScorePercentile: 67%VendorProductVersionmantisbtmantisbt𝑥≤ 1.2.18𝑥= Vulnerable software versionsUbuntu ReleasesUbuntu ProductCodenamemantiszestydneyakketydnexenialdnewilydnevividdneutopicdnetrustydnepreciseignoredlucidignoredCommon Weakness EnumerationCWE-287 - Improper AuthenticationWhen an actor claims to have a given identity, the software does not prove or insufficiently proves that the claim is correct.Referenceshttp://www.openwall.com/lists/oss-security/2015/01/18/11http://www.securitytracker.com/id/1031633https://bugzilla.redhat.com/show_bug.cgi?id=1183593https://exchange.xforce.ibmcloud.com/vulnerabilities/100213https://www.mantisbt.org/bugs/changelog_page.php?project=mantisbt&version=1.2.19https://www.mantisbt.org/bugs/view.php?id=17984http://www.openwall.com/lists/oss-security/2015/01/18/11http://www.securitytracker.com/id/1031633https://bugzilla.redhat.com/show_bug.cgi?id=1183593https://exchange.xforce.ibmcloud.com/vulnerabilities/100213https://www.mantisbt.org/bugs/changelog_page.php?project=mantisbt&version=1.2.19https://www.mantisbt.org/bugs/view.php?id=17984