Show filters
99 Total Results
Displaying 41-50 of 99
Sort by:
Attacker Value
Unknown

CVE-2017-1000133

Disclosure Date: November 03, 2017 (last updated November 26, 2024)
Mahara 15.04 before 15.04.8 and 15.10 before 15.10.4 and 16.04 before 16.04.2 are vulnerable to a user - in some circumstances causing another user's artefacts to be included in a Leap2a export of their own pages.
0
Attacker Value
Unknown

CVE-2017-1000135

Disclosure Date: November 03, 2017 (last updated November 26, 2024)
Mahara 1.8 before 1.8.7 and 1.9 before 1.9.5 and 1.10 before 1.10.3 and 15.04 before 15.04.0 are vulnerable as logged-in users can stay logged in after the institution they belong to is suspended.
0
Attacker Value
Unknown

CVE-2017-1000144

Disclosure Date: November 03, 2017 (last updated November 26, 2024)
Mahara 1.9 before 1.9.6 and 1.10 before 1.10.4 and 15.04 before 15.04.1 are vulnerable to a site admin or institution admin being able to place HTML and Javascript into an institution display name, which will be displayed to other users unescaped on some Mahara system pages.
0
Attacker Value
Unknown

CVE-2017-1000136

Disclosure Date: November 03, 2017 (last updated November 26, 2024)
Mahara 1.8 before 1.8.6 and 1.9 before 1.9.4 and 1.10 before 1.10.1 and 15.04 before 15.04.0 are vulnerable to old sessions not being invalidated after a password change.
0
Attacker Value
Unknown

CVE-2017-1000146

Disclosure Date: November 03, 2017 (last updated November 26, 2024)
Mahara 1.9 before 1.9.7 and 1.10 before 1.10.5 and 15.04 before 15.04.2 are vulnerable to the arbitrary execution of Javascript in the browser of a logged-in user because the title of the portfolio page was not being properly escaped in the AJAX script that updates the Add/remove watchlist link on artefact detail pages.
0
Attacker Value
Unknown

CVE-2017-1000171

Disclosure Date: November 03, 2017 (last updated November 26, 2024)
Mahara Mobile before 1.2.1 is vulnerable to passwords being sent to the Mahara access log in plain text.
0
Attacker Value
Unknown

CVE-2017-1000155

Disclosure Date: November 03, 2017 (last updated November 26, 2024)
Mahara 15.04 before 15.04.8 and 15.10 before 15.10.4 and 16.04 before 16.04.2 are vulnerable to profile pictures being accessed without any access control checks consequently allowing any of a user's uploaded profile pictures to be viewable by anyone, whether or not they were currently selected as the "default" or used in any pages.
0
Attacker Value
Unknown

CVE-2017-1000143

Disclosure Date: November 03, 2017 (last updated November 26, 2024)
Mahara 1.8 before 1.8.7 and 1.9 before 1.9.5 and 1.10 before 1.10.3 and 15.04 before 15.04.0 are vulnerable to users receiving watchlist notifications about pages they do not have access to anymore.
0
Attacker Value
Unknown

CVE-2017-1000152

Disclosure Date: November 03, 2017 (last updated November 26, 2024)
Mahara 15.04 before 15.04.7 and 15.10 before 15.10.3 running PHP 5.3 are vulnerable to one user being logged in as another user on a separate computer as the same session ID is served. This situation can occur when a user takes an action that forces another user to be logged out of Mahara, such as an admin changing another user's account settings.
0
Attacker Value
Unknown

CVE-2017-1000134

Disclosure Date: November 03, 2017 (last updated November 26, 2024)
Mahara 1.8 before 1.8.6 and 1.9 before 1.9.4 and 1.10 before 1.10.1 and 15.04 before 15.04.0 are vulnerable because group members can lose access to the group files they uploaded if another group member changes the access permissions on them.
0