Total vulnerabilities in the database
Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, allows authenticated users with editing privileges to delete other users by directly calling the editusers.cgi script with the "del" option.
Software | From | Fixed in |
---|---|---|
mozilla / bugzilla | 2.16-rc1 | 2.16-rc1.x |
mozilla / bugzilla | 2.16 | 2.16.x |
mozilla / bugzilla | 2.14.1 | 2.14.1.x |
mozilla / bugzilla | 2.14 | 2.14.x |