Bugzilla 3.2 before 3.2 RC2, 3.0 before 3.0.6, 2.22 before 2.22.6, 2.20 before 2.20.7, and other versions after 2.17.4 allows remote authenticated users to bypass moderation to approve and disapprove quips via a direct request to quips.cgi with the action parameter set to "approve."
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: redhat
Published: 2009-02-09T18:00:00
Updated: 2024-08-07T11:20:25.110Z
Reserved: 2009-02-09T00:00:00
Link: CVE-2008-6098

No data.

Status : Deferred
Published: 2009-02-09T18:30:00.170
Modified: 2025-04-09T00:30:58.490
Link: CVE-2008-6098
