Forums | Mahara Community

Security Announcements /
Information disclosure bugs in Mahara 1.2.8 and 1.3.5


This topic is closed. Only moderators and the group administrators can post new replies.
François Marier's profile picture
Posts: 411

09 May 2011, 21:00

Category: Information disclosure
Severity: Medium
Versions affected: < 1.2.9, < 1.3.6
Reported by: Mahara Team
Identifier: CVE-2011-1404

Many of the JSON structures returned by Mahara for its AJAX interactions included more information than what ought to be disclosed to the logged in user. New versions of Mahara limit this information to what is necessary for each page.

Upgrading to the latest version of Mahara is recommended for all sites.

1 result