MEDIUM
Cross-site request forgery (CSRF) vulnerability in xmlrpc.cgi in Bugzilla 4.0.2 through 4.0.4 and 4.1.1 through 4.2rc2, when mod_perl is used, allows remote attackers to hijack the authentication of arbitrary users for requests that modify the product's installation via the XML-RPC API
Published Feb 25, 2012
5.1
MEDIUMCVSS 2.0
EPSS 0.83%
Description
Affected products
Remediation
Metrics
References (3)
Change history (0)
No recorded changes yet.