CVE Vulnerabilities

CVE-2011-1404

Published: May 13, 2011 | Modified: Aug 17, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

Mahara before 1.3.6 does not properly restrict the data in responses to AJAX calls, which allows remote authenticated users to obtain sensitive information via a request associated with (1) blocktype/myfriends/myfriends.json.php, (2) json/usersearch.php, (3) group/membersearchresults.json.php, or (4) json/friendsearch.php, as demonstrated by information about friends and e-mail addresses.

Affected Software

Name Vendor Start Version End Version
Mahara Mahara 1.1.0 1.1.0
Mahara Mahara 1.1.6 1.1.6
Mahara Mahara 1.2.0 1.2.0
Mahara Mahara 0.9.1 0.9.1
Mahara Mahara 1.1.2 1.1.2
Mahara Mahara 1.2.3 1.2.3
Mahara Mahara 1.0.4 1.0.4
Mahara Mahara 1.1.7 1.1.7
Mahara Mahara 1.2.1 1.2.1
Mahara Mahara 1.3.2 1.3.2
Mahara Mahara 0.9.2 0.9.2
Mahara Mahara 1.0.1 1.0.1
Mahara Mahara 1.0.8 1.0.8
Mahara Mahara 1.2.0 1.2.0
Mahara Mahara 1.2.0 1.2.0
Mahara Mahara 1.0.12 1.0.12
Mahara Mahara 1.0.15 1.0.15
Mahara Mahara 1.0.6 1.0.6
Mahara Mahara 1.3.0 1.3.0
Mahara Mahara 1.0.9 1.0.9
Mahara Mahara 1.2.0 1.2.0
Mahara Mahara 1.3.0 1.3.0
Mahara Mahara 1.1.9 1.1.9
Mahara Mahara * 1.3.5
Mahara Mahara 1.0.5 1.0.5
Mahara Mahara 1.1 1.1
Mahara Mahara 1.2.0 1.2.0
Mahara Mahara 1.1.0 1.1.0
Mahara Mahara 1.1.4 1.1.4
Mahara Mahara 1.2.0 1.2.0
Mahara Mahara 1.2.0 1.2.0
Mahara Mahara 1.2.6 1.2.6
Mahara Mahara 1.3.0 1.3.0
Mahara Mahara 1.0.2 1.0.2
Mahara Mahara 1.1.0 1.1.0
Mahara Mahara 1.0.3 1.0.3
Mahara Mahara 1.0.13 1.0.13
Mahara Mahara 1.3.1 1.3.1
Mahara Mahara 1.0.10 1.0.10
Mahara Mahara 1.1.0 1.1.0
Mahara Mahara 1.1.1 1.1.1
Mahara Mahara 1.3.0 1.3.0
Mahara Mahara 1.1.8 1.1.8
Mahara Mahara 1.1.0 1.1.0
Mahara Mahara 1.2.4 1.2.4
Mahara Mahara 1.1.0 1.1.0
Mahara Mahara 1.3.0 1.3.0
Mahara Mahara 1.1.0 1.1.0
Mahara Mahara 1.2.2 1.2.2
Mahara Mahara 1.2.5 1.2.5
Mahara Mahara 1.1.3 1.1.3
Mahara Mahara 1.3.4 1.3.4
Mahara Mahara 1.0.7 1.0.7
Mahara Mahara 1.0.0 1.0.0
Mahara Mahara 1.1.0 1.1.0
Mahara Mahara 1.1.5 1.1.5
Mahara Mahara 1.2.0 1.2.0
Mahara Mahara 1.1.0 1.1.0
Mahara Mahara 1.1.0 1.1.0
Mahara Mahara 1.2.0 1.2.0
Mahara Mahara 1.3.3 1.3.3
Mahara Mahara 1.0.14 1.0.14
Mahara Mahara 1.3.0 1.3.0
Mahara Mahara 1.0.11 1.0.11
Mahara Mahara 0.9.0 0.9.0

References