Launchpad.net

CVE 2012-1121

MantisBT before 1.2.9 does not properly check permissions, which allows remote authenticated users with manager privileges to (1) modify or (2) delete global categories.

See the CVE page on Mitre.org for more details.