CVE: CVE-2005-2173

Export to Word

The Flag::validate and Flag::modify functions in Bugzilla 2.17.1 to 2.18.1 and 2.19.1 to 2.19.3 do not verify that the flag ID is appropriate for the given bug or attachment ID, which allows users to change flags on arbitrary bugs and obtain a bug summary via process_bug.cgi.

Threat-Mapped Scoring

Score: 0.0

Priority: Unclassified

EPSS

Score: 0.00384
Percentile: 0.58827

CVSS Scoring

CVSS v2 Score: 5.0

Severity:

Affected Products

← Back to Home