Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q7v7-wgvv-h4x9

Опубликовано: 02 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Cross-site request forgery (CSRF) vulnerability in Bugzilla before 3.2 before 3.2.1, 3.3 before 3.3.2, and other versions before 3.2 allows remote attackers to perform bug updating activities as other users via a link or IMG tag to process_bug.cgi.

Cross-site request forgery (CSRF) vulnerability in Bugzilla before 3.2 before 3.2.1, 3.3 before 3.3.2, and other versions before 3.2 allows remote attackers to perform bug updating activities as other users via a link or IMG tag to process_bug.cgi.

EPSS

Процентиль: 50%
0.00267
Низкий

Дефекты

CWE-352

Связанные уязвимости

ubuntu
почти 17 лет назад

Cross-site request forgery (CSRF) vulnerability in Bugzilla before 3.2 before 3.2.1, 3.3 before 3.3.2, and other versions before 3.2 allows remote attackers to perform bug updating activities as other users via a link or IMG tag to process_bug.cgi.

redhat
почти 17 лет назад

Cross-site request forgery (CSRF) vulnerability in Bugzilla before 3.2 before 3.2.1, 3.3 before 3.3.2, and other versions before 3.2 allows remote attackers to perform bug updating activities as other users via a link or IMG tag to process_bug.cgi.

nvd
почти 17 лет назад

Cross-site request forgery (CSRF) vulnerability in Bugzilla before 3.2 before 3.2.1, 3.3 before 3.3.2, and other versions before 3.2 allows remote attackers to perform bug updating activities as other users via a link or IMG tag to process_bug.cgi.

debian
почти 17 лет назад

Cross-site request forgery (CSRF) vulnerability in Bugzilla before 3.2 ...

EPSS

Процентиль: 50%
0.00267
Низкий

Дефекты

CWE-352