Cross-site request forgery (CSRF) vulnerability in editversions.cgi in Bugzilla before 2.22.1 and 2.23.x before 2.23.3 allows user-assisted remote attackers to create, modify, or delete arbitrary bug reports via a crafted URL.
2006-10-23T17:07:00.000
2025-04-09T00:30:58.490
Deferred
CVSSv2: 2.6 (LOW)
AV:N/AC:H/Au:N/C:N/I:P/A:N
4.9
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | mozilla | bugzilla | ≤ 2.22.1 | Yes |
Application | mozilla | bugzilla | 2.23 | Yes |
Application | mozilla | bugzilla | 2.23.1 | Yes |
Application | mozilla | bugzilla | 2.23.2 | Yes |