Bugzilla是基于Web的漏洞跟踪系统。 多个Bugzilla版本(2.17.1至2.18.1及2.19.1及2.19.3)中的Flag::validate和Flag::modify函数存在信息泄露漏洞。 由于没有检查flag ID与对应的Bug或attachment ID是否匹配,用户可以通过修改标记的方法,获取任意bug摘要信息。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet