The WebService in Bugzilla 3.1.3 allows remote authenticated users without canconfirm privileges to create NEW or ASSIGNED bug entries via a request to the XML-RPC interface, which bypasses the canconfirm check.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Bugzilla | Mozilla | 3.1.3 (including) | 3.1.3 (including) |