Loading...
Loading...
Cross-site request forgery (CSRF) vulnerability in attachment.cgi in Bugzilla 2.x, 3.x, and 4.0.x before 4.0.11; 4.1.x and 4.2.x before 4.2.7; and 4.3.x and 4.4.x before 4.4.1 allows remote attackers to hijack the authentication of arbitrary users for requests that commit an attachment change via an update action.
October 24, 2013
April 29, 2026
See which npm, PyPI, Go, and Maven packages are affected by CVE-2013-1734
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.