Description
|
|
A vulnerability has been identified in Bugzilla, which could be exploited to conduct cross-site request forgery attacks. This issue is caused due to the Attachment editing feature not validating calls to "attachment.cgi", which could be exploited by attackers to bypass security restrictions and manipulate certain data by tricking a user into visiting a malicious web page.
|