Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-57h3-4hgq-6hc9

Опубликовано: 29 апр. 2022
Источник: github
Github: Не прошло ревью

Описание

process_bug.cgi in Bugzilla 2.9 through 2.18rc2 and 2.19 from CVS does not check edit permissions on the keywords field, which allows remote authenticated users to modify the keywords in a bug via the keywordaction parameter.

process_bug.cgi in Bugzilla 2.9 through 2.18rc2 and 2.19 from CVS does not check edit permissions on the keywords field, which allows remote authenticated users to modify the keywords in a bug via the keywordaction parameter.

EPSS

Процентиль: 52%
0.00288
Низкий

Связанные уязвимости

nvd
почти 21 год назад

process_bug.cgi in Bugzilla 2.9 through 2.18rc2 and 2.19 from CVS does not check edit permissions on the keywords field, which allows remote authenticated users to modify the keywords in a bug via the keywordaction parameter.

debian
почти 21 год назад

process_bug.cgi in Bugzilla 2.9 through 2.18rc2 and 2.19 from CVS does ...

EPSS

Процентиль: 52%
0.00288
Низкий