CVE-2009-0481Cross-site Scripting in Mozilla Bugzilla

Severity
3.5LOWNVD
EPSS
0.2%
top 53.96%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 9
Latest updateMay 2

Description

Bugzilla 2.x before 2.22.7, 3.0 before 3.0.7, 3.2 before 3.2.1, and 3.3 before 3.3.2 allows remote authenticated users to conduct cross-site scripting (XSS) and related attacks by uploading HTML and JavaScript attachments that are rendered by web browsers.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 6.8 | Impact: 2.9

Affected Packages1 packages

NVDmozilla/bugzilla69 versions+68

🔴Vulnerability Details

2
GHSA
GHSA-47hm-8hq6-8r8f: Bugzilla 22022-05-02
CVEList
CVE-2009-0481: Bugzilla 22009-02-09

📋Vendor Advisories

1
Red Hat
bugzilla: XSS vulnerability via HTML and JavaScript attachments2009-02-09

💬Community

3
Bugzilla
CVE-2009-0481 bugzilla: XSS vulnerability via HTML and JavaScript attachments2009-02-09
Bugzilla
CVE-2008-4437 CVE-2008-6098, CVE-2009-048[13456] bugzilla: multiple issues [F10]2009-02-09
Bugzilla
CVE-2008-4437 CVE-2008-6098, CVE-2009-048[13456] bugzilla: multiple issues [F9]2009-02-09
CVE-2009-0481 — Cross-site Scripting in Mozilla | cvebase