Forums | Mahara Community

Security Announcements /
Information Disclosure in Mahara 1.4.0 and 1.3.6


This topic is closed. Only moderators and the group administrators can post new replies.
François Marier's profile picture
Posts: 411

03 November 2011, 17:46

Category: Information Disclosure
Severity: High
Versions affected: < 1.3.7, < 1.4.1
Reported by: Teemu Vesala
Identifier: CVE-2011-2774
Bug report: 798128

It was reported to us that previous versions of Mahara did not check user credentials before displaying private conversations between users on the reply page.

As this vulnerability affects the privacy of all Mahara users, we strongly recommend that all Mahara administrators upgrade to the latest version.

1 result