CVE-2017-1000131

MEDIUM

Mahara <15.04.8, 15.10 <15.10.4, 16.04 <16.04.2 - Info Disclosure

Title source: llm
STIX 2.1

Description

Mahara 15.04 before 15.04.8 and 15.10 before 15.10.4 and 16.04 before 16.04.2 are vulnerable to users staying logged in to their Mahara account even when they have been logged out of Moodle (when using MNet) as Mahara did not properly implement one of the MNet SSO API functions.

References (1)

Core 1
Core References
Exploit, Issue Tracking, Patch, Third Party Advisory x_refsource_misc
https://bugs.launchpad.net/mahara/+bug/1084336

Scores

CVSS v3 6.5
EPSS 0.0062
EPSS Percentile 44.8%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Details

CWE
CWE-613
Status published
Products (16)
mahara/mahara 15.04 rc1 (2 CPE variants)
mahara/mahara 15.04.0
mahara/mahara 15.04.1
mahara/mahara 15.04.2
mahara/mahara 15.04.3
mahara/mahara 15.04.4
mahara/mahara 15.04.5
mahara/mahara 15.04.6
mahara/mahara 15.04.7
mahara/mahara 16.04 rc1 (2 CPE variants)
... and 6 more
Published Nov 03, 2017
Tracked Since Feb 18, 2026