CVE Vulnerabilities

CVE-2007-5038

Published: Sep 24, 2007 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The offer_account_by_email function in User.pm in the WebService for Bugzilla before 3.0.2, and 3.1.x before 3.1.2, does not check the value of the createemailregexp parameter, which allows remote attackers to bypass intended restrictions on account creation.

Affected Software

NameVendorStart VersionEnd Version
BugzillaMozilla3.0.0 (including)3.0.0 (including)
BugzillaMozilla3.0.1 (including)3.0.1 (including)
BugzillaMozilla3.1.0 (including)3.1.0 (including)
BugzillaMozilla3.1.1 (including)3.1.1 (including)

References