CVE Vulnerabilities

CVE-2019-9708

Published: May 07, 2019 | Modified: Nov 21, 2024
CVSS 3.x
4.9
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

An issue was discovered in Mahara 17.10 before 17.10.8, 18.04 before 18.04.4, and 18.10 before 18.10.1. A site administrator can suspend the system user (root), causing all users to be locked out from the system.

Affected Software

NameVendorStart VersionEnd Version
MaharaMahara17.10.0 (including)17.10.8 (excluding)
MaharaMahara18.04.0 (including)18.04.4 (excluding)
MaharaMahara18.10.0 (including)18.10.1 (excluding)

References