Vulnerability Name: | CVE-2013-4431 | ||||||||
Assigned: | 2013-06-12 | ||||||||
Published: | 2014-05-19 | ||||||||
Updated: | 2014-05-19 | ||||||||
Summary: | Mahara before 1.5.12, 1.6.x before 1.6.7, and 1.7.x before 1.7.3 does not properly prevent access to blocks, which allows remote authenticated users to modify arbitrary blocks via the bock id in an edit request. | ||||||||
CVSS v3 Severity: | 4.6 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 5.5 Medium (CVSS v2 Vector: AV:N/AC:L/Au:S/C:N/I:P/A:P)
| ||||||||
Vulnerability Type: | CWE-264 | ||||||||
References: | Source: MITRE Type: CNA CVE-2013-4431 Source: MLIST Type: UNKNOWN [oss-security] 20131008 CVE request: mahara 1.7.3 Source: MLIST Type: UNKNOWN [oss-security] 20131015 Re: CVE request: mahara 1.7.3 Source: MLIST Type: UNKNOWN [oss-security] 20131015 Re: Re: CVE request: mahara 1.7.3 Source: CONFIRM Type: UNKNOWN https://bugs.launchpad.net/mahara/+bug/1233500 Source: CONFIRM Type: UNKNOWN https://mahara.org/interaction/forum/topic.php?id=5753 | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration 3: Denotes that component is vulnerable | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |