Cross-site request forgery (CSRF) vulnerability in attachment.cgi in Bugzilla 2.x, 3.x, and 4.x before 4.2rc1 allows remote attackers to hijack the authentication of arbitrary users for requests that upload attachments.
Loading...
Loading...
Cross-site request forgery (CSRF) vulnerability in attachment.cgi in Bugzilla 2.x, 3.x, and 4.x before 4.2rc1 allows remote attackers to hijack the authentication of arbitrary users for requests that upload attachments.
January 2, 2012
April 29, 2026
See which npm, PyPI, Go, and Maven packages are affected by CVE-2011-3669
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.