Vulnerability Name: | CVE-2017-1000145 (CCN-134456) | ||||||||||||
Assigned: | 2015-07-10 | ||||||||||||
Published: | 2015-07-10 | ||||||||||||
Updated: | 2019-10-03 | ||||||||||||
Summary: | Mahara 1.9 before 1.9.7 and 1.10 before 1.10.5 and 15.04 before 15.04.2 are vulnerable to anonymous comments being able to be placed on artefact detail pages even when the site administrator had disallowed anonymous comments. | ||||||||||||
CVSS v3 Severity: | 4.9 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N) 4.3 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C)
3.8 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 4.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:S/C:N/I:P/A:N)
| ||||||||||||
Vulnerability Type: | CWE-noinfo | ||||||||||||
Vulnerability Consequences: | Bypass Security | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2017-1000145 Source: CCN Type: Mahara Bugs: 1460368 Even if you disallow anonymous comments at the site level, you can still place anonymous comments on artefacts Source: MISC Type: Exploit, Issue Tracking, Patch, Third Party Advisory https://bugs.launchpad.net/mahara/+bug/1460368 Source: XF Type: UNKNOWN mahara-cve20171000145-sec-bypass(134456) Source: CCN Type: Mahara Web site Mahara | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration 3: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||
BACK |