CVE-2020-9387

MEDIUM

Mahara 19.04-19.04.5 and 19.10-19.10.3 - Unauthorized Exposure of Sensitive Account Information via Elasticsearch

Title source: llm
STIX 2.1

Description

In Mahara 19.04 before 19.04.5 and 19.10 before 19.10.3, account details are shared in the Elasticsearch results for accounts that are not accessible when the config setting 'Isolated institutions' is turned on.

References (2)

Core 2
Core References
Issue Tracking, Patch, Third Party Advisory x_refsource_confirm
https://bugs.launchpad.net/mahara/+bug/1836984
Vendor Advisory x_refsource_confirm
https://mahara.org/interaction/forum/topic.php?id=8612

Scores

CVSS v3 4.3
EPSS 0.0072
EPSS Percentile 49.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-200
Status published
Products (2)
mahara/mahara 20.04 rc1 (2 CPE variants)
mahara/mahara 19.04 - 19.04.5
Published Apr 30, 2020
Tracked Since Feb 18, 2026