CVE-2017-1000154
- EPSS 0.61%
- Published 03.11.2017 18:29:01
- Last modified 20.04.2025 01:37:25
Mahara 15.04 before 15.04.8 and 15.10 before 15.10.4 and 16.04 before 16.04.2 are vulnerable to some authentication methods, which do not use Mahara's built-in login form, still allowing users to log in even if their institution was expired or suspen...
CVE-2017-1000155
- EPSS 0.17%
- Published 03.11.2017 18:29:01
- Last modified 20.04.2025 01:37:25
Mahara 15.04 before 15.04.8 and 15.10 before 15.10.4 and 16.04 before 16.04.2 are vulnerable to profile pictures being accessed without any access control checks consequently allowing any of a user's uploaded profile pictures to be viewable by anyone...
CVE-2017-1000156
- EPSS 0.25%
- Published 03.11.2017 18:29:01
- Last modified 20.04.2025 01:37:25
Mahara 15.04 before 15.04.9 and 15.10 before 15.10.5 and 16.04 before 16.04.3 are vulnerable to a group's configuration page being editable by any group member even when they didn't have the admin role.
CVE-2017-1000157
- EPSS 0.25%
- Published 03.11.2017 18:29:01
- Last modified 20.04.2025 01:37:25
Mahara 15.04 before 15.04.13 and 16.04 before 16.04.7 and 16.10 before 16.10.4 and 17.04 before 17.04.2 are vulnerable to recording plain text passwords in the event_log table during the user creation process if full event logging was turned on.
CVE-2017-1000131
- EPSS 0.12%
- Published 03.11.2017 18:29:00
- Last modified 20.04.2025 01:37:25
Mahara 15.04 before 15.04.8 and 15.10 before 15.10.4 and 16.04 before 16.04.2 are vulnerable to users staying logged in to their Mahara account even when they have been logged out of Moodle (when using MNet) as Mahara did not properly implement one o...
CVE-2017-1000132
- EPSS 0.22%
- Published 03.11.2017 18:29:00
- Last modified 20.04.2025 01:37:25
Mahara 1.8 before 1.8.7 and 1.9 before 1.9.5 and 1.10 before 1.10.3 and 15.04 before 15.04.0 are vulnerable to a maliciously created .swf files that can have its code executed when a user tries to download the file.
CVE-2017-1000133
- EPSS 0.25%
- Published 03.11.2017 18:29:00
- Last modified 20.04.2025 01:37:25
Mahara 15.04 before 15.04.8 and 15.10 before 15.10.4 and 16.04 before 16.04.2 are vulnerable to a user - in some circumstances causing another user's artefacts to be included in a Leap2a export of their own pages.
CVE-2017-1000134
- EPSS 0.18%
- Published 03.11.2017 18:29:00
- Last modified 20.04.2025 01:37:25
Mahara 1.8 before 1.8.6 and 1.9 before 1.9.4 and 1.10 before 1.10.1 and 15.04 before 15.04.0 are vulnerable because group members can lose access to the group files they uploaded if another group member changes the access permissions on them.
CVE-2017-1000135
- EPSS 0.12%
- Published 03.11.2017 18:29:00
- Last modified 20.04.2025 01:37:25
Mahara 1.8 before 1.8.7 and 1.9 before 1.9.5 and 1.10 before 1.10.3 and 15.04 before 15.04.0 are vulnerable as logged-in users can stay logged in after the institution they belong to is suspended.
CVE-2017-1000136
- EPSS 0.15%
- Published 03.11.2017 18:29:00
- Last modified 20.04.2025 01:37:25
Mahara 1.8 before 1.8.6 and 1.9 before 1.9.4 and 1.10 before 1.10.1 and 15.04 before 15.04.0 are vulnerable to old sessions not being invalidated after a password change.