CVE Vulnerabilities

CVE-2017-1000145

Published: Nov 03, 2017 | Modified: Oct 03, 2019
CVSS 3.x
4.9
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

Mahara 1.9 before 1.9.7 and 1.10 before 1.10.5 and 15.04 before 15.04.2 are vulnerable to anonymous comments being able to be placed on artefact detail pages even when the site administrator had disallowed anonymous comments.

Affected Software

Name Vendor Start Version End Version
Mahara Mahara 1.9-rc1 (including) 1.9-rc1 (including)
Mahara Mahara 1.9.0 (including) 1.9.0 (including)
Mahara Mahara 1.9.1 (including) 1.9.1 (including)
Mahara Mahara 1.9.2 (including) 1.9.2 (including)
Mahara Mahara 1.9.3 (including) 1.9.3 (including)
Mahara Mahara 1.9.4 (including) 1.9.4 (including)
Mahara Mahara 1.9.5 (including) 1.9.5 (including)
Mahara Mahara 1.9.6 (including) 1.9.6 (including)

References