Lucene search

K
prionPRIOn knowledge basePRION:CVE-2013-1734
HistoryOct 24, 2013 - 10:53 a.m.

Cross site request forgery (csrf)

2013-10-2410:53:00
PRIOn knowledge base
www.prio-n.com
8

7.5 High

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

50.2%

Cross-site request forgery (CSRF) vulnerability in attachment.cgi in Bugzilla 2.x, 3.x, and 4.0.x before 4.0.11; 4.1.x and 4.2.x before 4.2.7; and 4.3.x and 4.4.x before 4.4.1 allows remote attackers to hijack the authentication of arbitrary users for requests that commit an attachment change via an update action.

7.5 High

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

50.2%