CVE Vulnerabilities

CVE-2011-1402

Published: May 13, 2011 | Modified: Aug 17, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Mahara before 1.3.6 allows remote authenticated users to bypass intended access restrictions, and suspend a user account, edit a view, visit a view, edit a plan artefact, read a plans block, read a plan artefact, edit a blog, read a blog block, read a blog artefact, or access a block, via a request associated with (1) admin/users/search.json.php, (2) view/newviewtoken.json.php, (3) lib/mahara.php, (4) artefact/plans/tasks.json.php, (5) artefact/plans/viewtasks.json.php, (6) artefact/blog/view/index.json.php, (7) artefact/blog/posts.json.php, or (8) blocktype/myfriends/myfriends.json.php, related to incorrect privilege enforcement, a missing user id check, and incorrect enforcement of the Overriding Start/Stop Dates setting.

Affected Software

Name Vendor Start Version End Version
Mahara Mahara 1.1.0 1.1.0
Mahara Mahara 1.1.6 1.1.6
Mahara Mahara 1.2.0 1.2.0
Mahara Mahara 0.9.1 0.9.1
Mahara Mahara 1.1.2 1.1.2
Mahara Mahara 1.2.3 1.2.3
Mahara Mahara 1.0.4 1.0.4
Mahara Mahara 1.1.7 1.1.7
Mahara Mahara 1.2.1 1.2.1
Mahara Mahara 1.3.2 1.3.2
Mahara Mahara 0.9.2 0.9.2
Mahara Mahara 1.0.1 1.0.1
Mahara Mahara 1.0.8 1.0.8
Mahara Mahara 1.2.0 1.2.0
Mahara Mahara 1.2.0 1.2.0
Mahara Mahara 1.0.12 1.0.12
Mahara Mahara 1.0.15 1.0.15
Mahara Mahara 1.0.6 1.0.6
Mahara Mahara 1.3.0 1.3.0
Mahara Mahara 1.0.9 1.0.9
Mahara Mahara 1.2.0 1.2.0
Mahara Mahara 1.3.0 1.3.0
Mahara Mahara 1.1.9 1.1.9
Mahara Mahara * 1.3.5
Mahara Mahara 1.0.5 1.0.5
Mahara Mahara 1.1 1.1
Mahara Mahara 1.2.0 1.2.0
Mahara Mahara 1.1.0 1.1.0
Mahara Mahara 1.1.4 1.1.4
Mahara Mahara 1.2.0 1.2.0
Mahara Mahara 1.2.0 1.2.0
Mahara Mahara 1.2.6 1.2.6
Mahara Mahara 1.3.0 1.3.0
Mahara Mahara 1.0.2 1.0.2
Mahara Mahara 1.1.0 1.1.0
Mahara Mahara 1.0.3 1.0.3
Mahara Mahara 1.0.13 1.0.13
Mahara Mahara 1.3.1 1.3.1
Mahara Mahara 1.0.10 1.0.10
Mahara Mahara 1.1.0 1.1.0
Mahara Mahara 1.1.1 1.1.1
Mahara Mahara 1.3.0 1.3.0
Mahara Mahara 1.1.8 1.1.8
Mahara Mahara 1.1.0 1.1.0
Mahara Mahara 1.2.4 1.2.4
Mahara Mahara 1.1.0 1.1.0
Mahara Mahara 1.3.0 1.3.0
Mahara Mahara 1.1.0 1.1.0
Mahara Mahara 1.2.2 1.2.2
Mahara Mahara 1.2.5 1.2.5
Mahara Mahara 1.1.3 1.1.3
Mahara Mahara 1.3.4 1.3.4
Mahara Mahara 1.0.7 1.0.7
Mahara Mahara 1.0.0 1.0.0
Mahara Mahara 1.1.0 1.1.0
Mahara Mahara 1.1.5 1.1.5
Mahara Mahara 1.2.0 1.2.0
Mahara Mahara 1.1.0 1.1.0
Mahara Mahara 1.1.0 1.1.0
Mahara Mahara 1.2.0 1.2.0
Mahara Mahara 1.3.3 1.3.3
Mahara Mahara 1.0.14 1.0.14
Mahara Mahara 1.3.0 1.3.0
Mahara Mahara 1.0.11 1.0.11
Mahara Mahara 0.9.0 0.9.0

References