Forums | Mahara Community

Security Announcements /
Cross-site Request Forgery in Mahara 1.4.0 and 1.3.6


This topic is closed. Only moderators and the group administrators can post new replies.
François Marier's profile picture
Posts: 411

03 November 2011, 17:52

Category: Cross-site Request Forgery
Severity: Medium
Versions affected: < 1.3.7, < 1.4.1
Reported by: Mahara Team
Identifier: CVE-2011-2773
Bug report: 800032

It was discovered that previous versions of Mahara did not check user credentials before processing a request to add a user to an institution. This could enable attackers to trick administrators into adding them to an institution.

If you make use of instititions, you are strongly encouraged to upgrade to the latest version.

1 result