Cross-site request forgery (CSRF) vulnerability in attachment.cgi in Bugzilla 2.x, 3.x, and 4.0.x before 4.0.11; 4.1.x and 4.2.x before 4.2.7; and 4.3.x and 4.4.x before 4.4.1 allows remote attackers to hijack the authentication of arbitrary users for requests that commit an attachment change via an update action.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mozilla

Published: 2022-10-03T16:14:47

Updated: 2022-10-03T16:14:47

Reserved: 2022-10-03T00:00:00


Link: CVE-2013-1734

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2013-10-24T10:53:09.537

Modified: 2013-10-24T16:35:46.270


Link: CVE-2013-1734

JSON object: View

cve-icon Redhat Information

No data.

CWE