CVE-2020-9282

MEDIUM

Mahara 18.10.0-18.10.4, 19.04.0-19.04.3, 19.10.0-19.10.1 - Sensitive Information Exposure via Edit Access

Title source: llm
STIX 2.1

Description

In Mahara 18.10 before 18.10.5, 19.04 before 19.04.4, and 19.10 before 19.10.2, certain personal information is discoverable inspecting network responses on the 'Edit access' screen when sharing portfolios.

References (2)

Core 2
Core References
Issue Tracking, Third Party Advisory x_refsource_misc
https://bugs.launchpad.net/mahara/+bug/1863043
Vendor Advisory x_refsource_confirm
https://mahara.org/interaction/forum/topic.php?id=8590

Scores

CVSS v3 6.5
EPSS 0.0092
EPSS Percentile 55.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-200
Status published
Products (1)
mahara/mahara 18.10.0 - 18.10.5
Published Mar 09, 2020
Tracked Since Feb 18, 2026