6.8

CVE-2012-2246

Mahara 1.4.x before 1.4.5 and 1.5.x before 1.5.4 allows remote attackers to conduct clickjacking attacks to delete arbitrary users and bypass CSRF protection via account/delete.php.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Mahara ≫ Mahara Version 1.4 Update rc1
Mahara ≫ Mahara Version 1.4 Update rc2
Mahara ≫ Mahara Version 1.4 Update rc3
Mahara ≫ Mahara Version 1.4 Update rc4
Mahara ≫ Mahara Version 1.4.0
Mahara ≫ Mahara Version 1.4.1
Mahara ≫ Mahara Version 1.4.2
Mahara ≫ Mahara Version 1.4.3
Mahara ≫ Mahara Version 1.4.4
Mahara ≫ Mahara Version 1.5 Update rc1
Mahara ≫ Mahara Version 1.5 Update rc2
Mahara ≫ Mahara Version 1.5.0
Mahara ≫ Mahara Version 1.5.1
Mahara ≫ Mahara Version 1.5.2
Mahara ≫ Mahara Version 1.5.3
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.34% 0.676
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://www.debian.org/security/2012/dsa-2591
https://bugs.launchpad.net/mahara/+bug/1057240
https://exchange.xforce.ibmcloud.com/vulnerabilities/79273
https://mahara.org/interaction/forum/topic.php?id=4939
Vendor Advisory