Forums | Mahara Community

Security Announcements /
Privilege escalations in Mahara 1.2.8 and 1.3.5


This topic is closed. Only moderators and the group administrators can post new replies.
François Marier's profile picture
Posts: 411

09 May 2011, 20:45

Category: Privilege escalation
Severity: High
Versions affected: < 1.2.9, < 1.3.6
Reported by: Mahara Team
Identifier: CVE-2011-1402

It was discovered that previous versions of Mahara did not check user credentials before adding a secret URL to a view or suspending a user.

We strongly urge all Mahara administrators to upgrade to the latest version.

1 result