First published: Fri Jan 28 2011(Updated: )
Cross-site scripting (XSS) vulnerability in Bugzilla 3.7.1, 3.7.2, 3.7.3, and 4.0rc1 allows remote attackers to inject arbitrary web script or HTML via the real name field of a user account, related to the AutoComplete widget in YUI.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Bugzilla | =3.7.2 | |
Mozilla Bugzilla | =3.7.1 | |
Mozilla Bugzilla | =3.7.3 | |
Mozilla Bugzilla | =4.0-rc1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-4569 is classified as a medium severity cross-site scripting (XSS) vulnerability.
To fix CVE-2010-4569, update Bugzilla to a version later than 4.0rc1 that includes the necessary security patches.
CVE-2010-4569 affects Bugzilla versions 3.7.1, 3.7.2, 3.7.3, and 4.0rc1.
CVE-2010-4569 allows remote attackers to inject malicious scripts via the real name field of user accounts.
If unable to update, ensure that user input is properly sanitized to reduce the risk of XSS attacks associated with CVE-2010-4569.