CyberRota
Live Feed
Return to register
Case File

CVE-2012-4199

MEDIUM · CVSS 4.3 EPSS 0.96%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2012-11-16 · Last synced 2026-08-04

Field Assessment

AI analysis pending.

CVE
CVE-2012-4199
Severity
MEDIUM
CVSS
4.3
EPSS
0.96%
Java

Original Filing — NVD Description

template/en/default/bug/field-events.js.tmpl in Bugzilla 3.x before 3.6.12, 3.7.x and 4.0.x before 4.0.9, 4.1.x and 4.2.x before 4.2.4, and 4.3.x and 4.4.x before 4.4rc1 generates JavaScript function calls containing private product names or private component names in certain circumstances involving custom-field visibility control, which allows remote attackers to obtain sensitive information by reading HTML source code.