CVE Vulnerabilities

CVE-2011-1404

Published: May 13, 2011 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Mahara before 1.3.6 does not properly restrict the data in responses to AJAX calls, which allows remote authenticated users to obtain sensitive information via a request associated with (1) blocktype/myfriends/myfriends.json.php, (2) json/usersearch.php, (3) group/membersearchresults.json.php, or (4) json/friendsearch.php, as demonstrated by information about friends and e-mail addresses.

Affected Software

NameVendorStart VersionEnd Version
MaharaMahara*1.3.5 (including)
MaharaMahara0.9.0 (including)0.9.0 (including)
MaharaMahara0.9.1 (including)0.9.1 (including)
MaharaMahara0.9.2 (including)0.9.2 (including)
MaharaMahara1.0.0 (including)1.0.0 (including)
MaharaMahara1.0.1 (including)1.0.1 (including)
MaharaMahara1.0.2 (including)1.0.2 (including)
MaharaMahara1.0.3 (including)1.0.3 (including)
MaharaMahara1.0.4 (including)1.0.4 (including)
MaharaMahara1.0.5 (including)1.0.5 (including)
MaharaMahara1.0.6 (including)1.0.6 (including)
MaharaMahara1.0.7 (including)1.0.7 (including)
MaharaMahara1.0.8 (including)1.0.8 (including)
MaharaMahara1.0.9 (including)1.0.9 (including)
MaharaMahara1.0.10 (including)1.0.10 (including)
MaharaMahara1.0.11 (including)1.0.11 (including)
MaharaMahara1.0.12 (including)1.0.12 (including)
MaharaMahara1.0.13 (including)1.0.13 (including)
MaharaMahara1.0.14 (including)1.0.14 (including)
MaharaMahara1.0.15 (including)1.0.15 (including)
MaharaMahara1.1 (including)1.1 (including)
MaharaMahara1.1.0 (including)1.1.0 (including)
MaharaMahara1.1.0-alpha1 (including)1.1.0-alpha1 (including)
MaharaMahara1.1.0-alpha2 (including)1.1.0-alpha2 (including)
MaharaMahara1.1.0-alpha3 (including)1.1.0-alpha3 (including)
MaharaMahara1.1.0-beta1 (including)1.1.0-beta1 (including)
MaharaMahara1.1.0-beta2 (including)1.1.0-beta2 (including)
MaharaMahara1.1.0-beta3 (including)1.1.0-beta3 (including)
MaharaMahara1.1.0-beta4 (including)1.1.0-beta4 (including)
MaharaMahara1.1.0-rc1 (including)1.1.0-rc1 (including)
MaharaMahara1.1.0-rc2 (including)1.1.0-rc2 (including)
MaharaMahara1.1.1 (including)1.1.1 (including)
MaharaMahara1.1.2 (including)1.1.2 (including)
MaharaMahara1.1.3 (including)1.1.3 (including)
MaharaMahara1.1.4 (including)1.1.4 (including)
MaharaMahara1.1.5 (including)1.1.5 (including)
MaharaMahara1.1.6 (including)1.1.6 (including)
MaharaMahara1.1.7 (including)1.1.7 (including)
MaharaMahara1.1.8 (including)1.1.8 (including)
MaharaMahara1.1.9 (including)1.1.9 (including)
MaharaMahara1.2.0 (including)1.2.0 (including)
MaharaMahara1.2.0-alpha1 (including)1.2.0-alpha1 (including)
MaharaMahara1.2.0-alpha2 (including)1.2.0-alpha2 (including)
MaharaMahara1.2.0-alpha3 (including)1.2.0-alpha3 (including)
MaharaMahara1.2.0-beta1 (including)1.2.0-beta1 (including)
MaharaMahara1.2.0-beta2 (including)1.2.0-beta2 (including)
MaharaMahara1.2.0-beta3 (including)1.2.0-beta3 (including)
MaharaMahara1.2.0-beta4 (including)1.2.0-beta4 (including)
MaharaMahara1.2.0-rc1 (including)1.2.0-rc1 (including)
MaharaMahara1.2.1 (including)1.2.1 (including)
MaharaMahara1.2.2 (including)1.2.2 (including)
MaharaMahara1.2.3 (including)1.2.3 (including)
MaharaMahara1.2.4 (including)1.2.4 (including)
MaharaMahara1.2.5 (including)1.2.5 (including)
MaharaMahara1.2.6 (including)1.2.6 (including)
MaharaMahara1.3.0 (including)1.3.0 (including)
MaharaMahara1.3.0-beta1 (including)1.3.0-beta1 (including)
MaharaMahara1.3.0-beta2 (including)1.3.0-beta2 (including)
MaharaMahara1.3.0-beta3 (including)1.3.0-beta3 (including)
MaharaMahara1.3.0-beta4 (including)1.3.0-beta4 (including)
MaharaMahara1.3.0-rc1 (including)1.3.0-rc1 (including)
MaharaMahara1.3.1 (including)1.3.1 (including)
MaharaMahara1.3.2 (including)1.3.2 (including)
MaharaMahara1.3.3 (including)1.3.3 (including)
MaharaMahara1.3.4 (including)1.3.4 (including)
MaharaUbuntulucid*
MaharaUbuntumaverick*
MaharaUbuntunatty*
MaharaUbuntuupstream*

References