Mahara

Mahara

110 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.21%
  • Veröffentlicht 30.01.2018 19:29:00
  • Zuletzt bearbeitet 21.11.2024 03:04:15

An issue was discovered in Mahara before 18.10.0. It mishandled user requests that could discontinue a user's ability to maintain their own account (changing username, changing primary email address, deleting account). The correct behavior was to eit...

Exploit
  • EPSS 0.38%
  • Veröffentlicht 03.11.2017 18:29:01
  • Zuletzt bearbeitet 13.05.2026 00:24:29

Mahara 15.04 before 15.04.10 and 15.10 before 15.10.6 and 16.04 before 16.04.4 are vulnerable to incorrect access control after the password reset link is sent via email and then user changes default email, Mahara fails to invalidate old link.Consequ...

Exploit
  • EPSS 0.61%
  • Veröffentlicht 03.11.2017 18:29:01
  • Zuletzt bearbeitet 13.05.2026 00:24:29

Mahara 15.04 before 15.04.8 and 15.10 before 15.10.4 and 16.04 before 16.04.2 are vulnerable to some authentication methods, which do not use Mahara's built-in login form, still allowing users to log in even if their institution was expired or suspen...

Exploit
  • EPSS 0.17%
  • Veröffentlicht 03.11.2017 18:29:01
  • Zuletzt bearbeitet 13.05.2026 00:24:29

Mahara 15.04 before 15.04.8 and 15.10 before 15.10.4 and 16.04 before 16.04.2 are vulnerable to profile pictures being accessed without any access control checks consequently allowing any of a user's uploaded profile pictures to be viewable by anyone...

Exploit
  • EPSS 0.25%
  • Veröffentlicht 03.11.2017 18:29:01
  • Zuletzt bearbeitet 13.05.2026 00:24:29

Mahara 15.04 before 15.04.9 and 15.10 before 15.10.5 and 16.04 before 16.04.3 are vulnerable to a group's configuration page being editable by any group member even when they didn't have the admin role.

Exploit
  • EPSS 0.25%
  • Veröffentlicht 03.11.2017 18:29:01
  • Zuletzt bearbeitet 13.05.2026 00:24:29

Mahara 15.04 before 15.04.13 and 16.04 before 16.04.7 and 16.10 before 16.10.4 and 17.04 before 17.04.2 are vulnerable to recording plain text passwords in the event_log table during the user creation process if full event logging was turned on.

Exploit
  • EPSS 0.12%
  • Veröffentlicht 03.11.2017 18:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

Mahara 15.04 before 15.04.8 and 15.10 before 15.10.4 and 16.04 before 16.04.2 are vulnerable to users staying logged in to their Mahara account even when they have been logged out of Moodle (when using MNet) as Mahara did not properly implement one o...

Exploit
  • EPSS 0.22%
  • Veröffentlicht 03.11.2017 18:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

Mahara 1.8 before 1.8.7 and 1.9 before 1.9.5 and 1.10 before 1.10.3 and 15.04 before 15.04.0 are vulnerable to a maliciously created .swf files that can have its code executed when a user tries to download the file.

  • EPSS 0.25%
  • Veröffentlicht 03.11.2017 18:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

Mahara 15.04 before 15.04.8 and 15.10 before 15.10.4 and 16.04 before 16.04.2 are vulnerable to a user - in some circumstances causing another user's artefacts to be included in a Leap2a export of their own pages.

Exploit
  • EPSS 0.18%
  • Veröffentlicht 03.11.2017 18:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

Mahara 1.8 before 1.8.6 and 1.9 before 1.9.4 and 1.10 before 1.10.1 and 15.04 before 15.04.0 are vulnerable because group members can lose access to the group files they uploaded if another group member changes the access permissions on them.