Description
Trac 0.11.6 does not properly check workflow permissions before modifying a ticket. This can be exploited by an attacker to change the status and resolution of tickets without having proper permissions.
Remediation
References
Related Vulnerabilities
WordPress Plugin Multi Plugin Installer Arbitrary File Disclosure (1.1.0)
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2011-4297)
Play Framework Improper Restriction of XML External Entity Reference Vulnerability (CVE-2014-3630)
Apache HTTP Server CVE-2012-0053 Vulnerability (CVE-2012-0053)