Mahara 1.8 before 1.8.6 and 1.9 before 1.9.4 and 1.10 before 1.10.1 and 15.04 before 15.04.0 are vulnerable because group members can lose access to the group files they uploaded if another group member changes the access permissions on them.
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Mahara | Mahara | 1.8-rc1 (including) | 1.8-rc1 (including) |
Mahara | Mahara | 1.8-rc2 (including) | 1.8-rc2 (including) |
Mahara | Mahara | 1.8.0 (including) | 1.8.0 (including) |
Mahara | Mahara | 1.8.1 (including) | 1.8.1 (including) |
Mahara | Mahara | 1.8.2 (including) | 1.8.2 (including) |
Mahara | Mahara | 1.8.3 (including) | 1.8.3 (including) |
Mahara | Mahara | 1.8.4 (including) | 1.8.4 (including) |
Mahara | Mahara | 1.8.5 (including) | 1.8.5 (including) |