Vulnerability Details CVE-2012-0453
Cross-site request forgery (CSRF) vulnerability in xmlrpc.cgi in Bugzilla 4.0.2 through 4.0.4 and 4.1.1 through 4.2rc2, when mod_perl is used, allows remote attackers to hijack the authentication of arbitrary users for requests that modify the product's installation via the XML-RPC API.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 33.5%
CVSS Severity
CVSS v2 Score 5.1
Products affected by CVE-2012-0453
-
cpe:2.3:a:mozilla:bugzilla:4.0.2
-
cpe:2.3:a:mozilla:bugzilla:4.0.3
-
cpe:2.3:a:mozilla:bugzilla:4.0.4
-
cpe:2.3:a:mozilla:bugzilla:4.1.1
-
cpe:2.3:a:mozilla:bugzilla:4.1.2
-
cpe:2.3:a:mozilla:bugzilla:4.1.3
-
cpe:2.3:a:mozilla:bugzilla:4.2