Vulnerabilities > Mahara > Mahara > 15.04.1

DATE CVE VULNERABILITY TITLE RISK
2017-11-03 CVE-2017-1000153 Incorrect Permission Assignment for Critical Resource vulnerability in Mahara
Mahara 15.04 before 15.04.10 and 15.10 before 15.10.6 and 16.04 before 16.04.4 are vulnerable to incorrect access control after the password reset link is sent via email and then user changes default email, Mahara fails to invalidate old link.Consequently the link in email can be used to gain access to the user's account.
network
low complexity
mahara CWE-732
7.5
2017-11-03 CVE-2017-1000152 Unspecified vulnerability in Mahara
Mahara 15.04 before 15.04.7 and 15.10 before 15.10.3 running PHP 5.3 are vulnerable to one user being logged in as another user on a separate computer as the same session ID is served.
network
low complexity
mahara
7.5
2017-11-03 CVE-2017-1000151 Information Exposure vulnerability in Mahara
Mahara 15.04 before 15.04.9 and 15.10 before 15.10.5 and 16.04 before 16.04.3 are vulnerable to passwords or other sensitive information being passed by unusual parameters to end up in an error log.
network
low complexity
mahara CWE-200
5.0
2017-11-03 CVE-2017-1000150 Session Fixation vulnerability in Mahara
Mahara 15.04 before 15.04.7 and 15.10 before 15.10.3 are vulnerable to prevent session IDs from being regenerated on login or logout.
network
low complexity
mahara CWE-384
6.5
2017-11-03 CVE-2017-1000149 Cross-site Scripting vulnerability in Mahara
Mahara 1.10 before 1.10.9 and 15.04 before 15.04.6 and 15.10 before 15.10.2 are vulnerable to XSS due to window.opener (target="_blank" and window.open())
network
mahara CWE-79
3.5
2017-11-03 CVE-2017-1000148 Deserialization of Untrusted Data vulnerability in Mahara
Mahara 15.04 before 15.04.8 and 15.10 before 15.10.4 and 16.04 before 16.04.2 are vulnerable to PHP code execution as Mahara would pass portions of the XML through the PHP "unserialize()" function when importing a skin from an XML file.
network
low complexity
mahara CWE-502
6.5
2017-11-03 CVE-2017-1000147 Cross-Site Request Forgery (CSRF) vulnerability in Mahara
Mahara 1.9 before 1.9.8 and 1.10 before 1.10.6 and 15.04 before 15.04.3 are vulnerable to perform a cross-site request forgery (CSRF) attack on the uploader contained in Mahara's filebrowser widget.
network
mahara CWE-352
6.0
2017-11-03 CVE-2017-1000146 Cross-site Scripting vulnerability in Mahara
Mahara 1.9 before 1.9.7 and 1.10 before 1.10.5 and 15.04 before 15.04.2 are vulnerable to the arbitrary execution of Javascript in the browser of a logged-in user because the title of the portfolio page was not being properly escaped in the AJAX script that updates the Add/remove watchlist link on artefact detail pages.
network
mahara CWE-79
3.5
2017-11-03 CVE-2017-1000145 Unspecified vulnerability in Mahara
Mahara 1.9 before 1.9.7 and 1.10 before 1.10.5 and 15.04 before 15.04.2 are vulnerable to anonymous comments being able to be placed on artefact detail pages even when the site administrator had disallowed anonymous comments.
network
low complexity
mahara
4.0
2017-11-03 CVE-2017-1000133 Information Exposure vulnerability in Mahara
Mahara 15.04 before 15.04.8 and 15.10 before 15.10.4 and 16.04 before 16.04.2 are vulnerable to a user - in some circumstances causing another user's artefacts to be included in a Leap2a export of their own pages.
network
low complexity
mahara CWE-200
5.0