Forums | Mahara Community

Security Announcements /
Cross-site request forgeries in Mahara 1.2.8 and 1.3.5


This topic is closed. Only moderators and the group administrators can post new replies.
François Marier's profile picture
Posts: 411

09 May 2011, 20:49

Category: Cross-site request forgery
Severity: Critical
Versions affected: < 1.2.9, < 1.3.6
Reported by: Bart van Delft
Identifier: CVE-2011-1403

Due to a misconfiguration of the Pieform package in Mahara, the cross-site request forgery protection mechanism that Mahara relies on to harden its form was not working and was essentially disabled.

This is a critical vulnerability which could allow attackers to trick other users (for example administrators) into performing malicious actions on behalf of the attacker. Most Mahara forms are vulnerable.

All sites are urged to upgrade now.

1 result