CVE-2006-2420Cross-site Scripting in Mozilla Bugzilla

Severity
4.3MEDIUMNVD
EPSS
0.7%
top 28.26%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 16
Latest updateMay 1

Description

Bugzilla 2.20rc1 through 2.20 and 2.21.1, when using RSS 1.0, allows remote attackers to conduct cross-site scripting (XSS) attacks via a title element with HTML encoded sequences such as ">", which are automatically decoded by some RSS readers. NOTE: this issue is not in Bugzilla itself, but rather due to design or documentation inconsistencies within RSS, or implementation vulnerabilities in RSS readers. While this issue normally would not be included in CVE, it is being identified since the B

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages1 packages

NVDmozilla/bugzilla2.20, 2.21, 2.21.1+2

Patches

🔴Vulnerability Details

2
GHSA
GHSA-w532-f824-3jqj: Bugzilla 22022-05-01
CVEList
CVE-2006-2420: Bugzilla 22006-05-16