Total vulnerabilities in the database
bug_report.php in MantisBT before 1.2.18 allows remote attackers to assign arbitrary issues via the handler_id parameter.
CVSS v2:
CWEs:
OWASP TOP 10: