CVE-2016-2803: XSS
Cross-site scripting (XSS) vulnerability in the dependency graphs in Bugzilla 2.16rc1 through 4.4.11, and 4.5.1 through 5.0.2 allows remote attackers to inject arbitrary web script or HTML.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-2803?
CVE-2016-2803 is classified as a moderate severity vulnerability due to the possibility of cross-site scripting (XSS) attacks.
How do I fix CVE-2016-2803?
To fix CVE-2016-2803, update your Bugzilla installation to version 5.0.3 or later, as these versions contain patches for the vulnerability.
What types of software are affected by CVE-2016-2803?
CVE-2016-2803 affects Bugzilla versions from 2.16rc1 through 4.4.11, and 4.5.1 through 5.0.2.
What can attackers do with CVE-2016-2803?
Attackers exploiting CVE-2016-2803 can inject arbitrary web scripts or HTML into the affected application, potentially compromising user data.
Is there a known exploit for CVE-2016-2803?
Yes, CVE-2016-2803 has been reported as actively exploitable, and users are encouraged to apply updates immediately.