Description
Trac 0.11.6 does not properly check workflow permissions before modifying a ticket. This can be exploited by an attacker to change the status and resolution of tickets without having proper permissions.
Remediation
References
Related Vulnerabilities
MySQL CVE-2021-35628 Vulnerability (CVE-2021-35628)
WordPress Plugin WP Post Popup Directory Traversal (2.0)
Plone CMS Server-Side Request Forgery (SSRF) Vulnerability (CVE-2021-33926)
MediaWiki Resource Management Errors Vulnerability (CVE-2015-8002)
Apache HTTP Server CVE-2024-40725 Vulnerability (CVE-2024-40725)