Mahara 15.04 before 15.04.10 and 15.10 before 15.10.6 and 16.04 before 16.04.4 are vulnerable to incorrect access control after the password reset link is sent via email and then user changes default email, Mahara fails to invalidate old link.Consequently the link in email can be used to gain access to the user's account.
References
Link | Resource |
---|---|
https://bugs.launchpad.net/mahara/+bug/1577251 | Exploit Issue Tracking Patch Third Party Advisory |
https://bugs.launchpad.net/mahara/+bug/1577251 | Exploit Issue Tracking Patch Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
History
21 Nov 2024, 03:04
Type | Values Removed | Values Added |
---|---|---|
References | () https://bugs.launchpad.net/mahara/+bug/1577251 - Exploit, Issue Tracking, Patch, Third Party Advisory |
Information
Published : 2017-11-03 18:29
Updated : 2024-11-21 03:04
NVD link : CVE-2017-1000153
Mitre link : CVE-2017-1000153
CVE.ORG link : CVE-2017-1000153
JSON object : View
Products Affected
mahara
- mahara
CWE
CWE-732
Incorrect Permission Assignment for Critical Resource