Forums | Mahara Community
Security Announcements
/
Information disclosure bugs in Mahara 1.2.8 and 1.3.5
09 May 2011, 21:00
Category: | Information disclosure |
Severity: | Medium |
Versions affected: | < 1.2.9, < 1.3.6 |
Reported by: | Mahara Team |
Identifier: | CVE-2011-1404 |
Many of the JSON structures returned by Mahara for its AJAX interactions included more information than what ought to be disclosed to the logged in user. New versions of Mahara limit this information to what is necessary for each page.
Upgrading to the latest version of Mahara is recommended for all sites.