9.8

CVE-2017-1000153

Exploit

Mahara 15.04 before 15.04.10 and 15.10 before 15.10.6 and 16.04 before 16.04.4 are vulnerable to incorrect access control after the password reset link is sent via email and then user changes default email, Mahara fails to invalidate old link.Consequently the link in email can be used to gain access to the user's account.

Data is provided by the National Vulnerability Database (NVD)
MaharaMahara Version15.04 Updaterc1
MaharaMahara Version15.04 Updaterc2
MaharaMahara Version15.04.0
MaharaMahara Version15.04.1
MaharaMahara Version15.04.2
MaharaMahara Version15.04.3
MaharaMahara Version15.04.4
MaharaMahara Version15.04.5
MaharaMahara Version15.04.6
MaharaMahara Version15.04.7
MaharaMahara Version15.04.8
MaharaMahara Version15.04.9
MaharaMahara Version16.04 Updaterc1
MaharaMahara Version16.04 Updaterc2
MaharaMahara Version16.04.0
MaharaMahara Version16.04.1
MaharaMahara Version16.04.2
MaharaMahara Version16.04.3
MaharaMahara Version15.10.0
MaharaMahara Version15.10.1
MaharaMahara Version15.10.2
MaharaMahara Version15.10.3
MaharaMahara Version15.10.4
MaharaMahara Version15.10.5
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.38% 0.588
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-732 Incorrect Permission Assignment for Critical Resource

The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.