Vulnerability Details CVE-2009-2125
delete_bug.php in Elvin before 1.2.1 does not require administrative privileges, which allows remote authenticated users to bypass intended access restrictions and delete arbitrary bugs.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 36.5%
CVSS Severity
CVSS v2 Score 4.0
Products affected by CVE-2009-2125
-
cpe:2.3:a:elvinbts:elvinbts:*
-
cpe:2.3:a:elvinbts:elvinbts:1.1.0