Forums | Mahara Community
Security Announcements
/
Cross-site request forgeries in Mahara 1.2.8 and 1.3.5
09 May 2011, 20:49
Category: | Cross-site request forgery |
Severity: | Critical |
Versions affected: | < 1.2.9, < 1.3.6 |
Reported by: | Bart van Delft |
Identifier: | CVE-2011-1403 |
Due to a misconfiguration of the Pieform package in Mahara, the cross-site request forgery protection mechanism that Mahara relies on to harden its form was not working and was essentially disabled.
This is a critical vulnerability which could allow attackers to trick other users (for example administrators) into performing malicious actions on behalf of the attacker. Most Mahara forms are vulnerable.
All sites are urged to upgrade now.