Medium
CVSS 5.5
Overview
Bugzilla 2.16.10, 2.17 through 2.18.4, and 2.20 does not properly handle certain characters in the mostfreqthreshold parameter in duplicates.cgi, which allows remote attackers to trigger a SQL error.
Bugzilla 2.16.10, 2.17 through 2.18.4, and 2.20 does not properly handle certain...
Bugzilla 2.16.10, 2.17 through 2.18.4, and 2.20 does not properly handle certain characters in the mostfreqthreshold parameter in duplicates.cgi, which allows remote attackers to trigger a SQL error.
This vulnerability is rated 🟡 MEDIUM.
Recommended actions: