Vulnerability Name: | CVE-2018-11565 (CCN-144665) | ||||||||||||
Assigned: | 2018-05-23 | ||||||||||||
Published: | 2018-05-23 | ||||||||||||
Updated: | 2018-07-03 | ||||||||||||
Summary: | Mahara 17.04 before 17.04.8 and 17.10 before 17.10.5 and 18.04 before 18.04.1 are vulnerable to mentioning the usernames that are already taken by people registered in the system rather than masking that information. | ||||||||||||
CVSS v3 Severity: | 5.3 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N) 4.6 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C)
4.6 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
| ||||||||||||
Vulnerability Type: | CWE-200 | ||||||||||||
Vulnerability Consequences: | Obtain Information | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2018-11565 Source: CCN Type: Launchpad Bug #1772774 change error message when changing username Source: CONFIRM Type: Issue Tracking, Patch, Vendor Advisory https://bugs.launchpad.net/mahara/+bug/1772774 Source: XF Type: UNKNOWN mahara-cve201811565-info-disc(144665) Source: CCN Type: Mahara Web site Mahara Source: CONFIRM Type: Vendor Advisory https://mahara.org/interaction/forum/topic.php?id=8271 Source: CCN Type: WhiteSource Vulnerability Database CVE-2018-11565 | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||||||
BACK |