CVE-2012-5884

Mozilla Bugzilla - Information Disclosure

Title source: rule

Description

The User.get method in Bugzilla/WebService/User.pm in Bugzilla 4.3.2 allows remote attackers to obtain sensitive information about the saved searches of arbitrary users via an XMLRPC request or a JSONRPC request, a different vulnerability than CVE-2012-4198.

Scores

EPSS 0.0026
EPSS Percentile 49.1%

Classification

CWE
CWE-200
Status draft

Affected Products (1)

mozilla/bugzilla

Timeline

Published Nov 16, 2012
Tracked Since Feb 18, 2026