CVE Vulnerabilities

CVE-2009-2125

Published: Jun 19, 2009 | Modified: Jun 23, 2009
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

delete_bug.php in Elvin before 1.2.1 does not require administrative privileges, which allows remote authenticated users to bypass intended access restrictions and delete arbitrary bugs.

Affected Software

Name Vendor Start Version End Version
Elvinbts Elvinbts * 1.2.0 (including)
Elvinbts Elvinbts 1.1.0 (including) 1.1.0 (including)

References