Forums | Mahara Community
Security Announcements
/
Information Disclosure in Mahara 1.4.0 and 1.3.6
03 November 2011, 17:46
Category: | Information Disclosure |
Severity: | High |
Versions affected: | < 1.3.7, < 1.4.1 |
Reported by: | Teemu Vesala |
Identifier: | CVE-2011-2774 |
Bug report: | 798128 |
It was reported to us that previous versions of Mahara did not check user credentials before displaying private conversations between users on the reply page.
As this vulnerability affects the privacy of all Mahara users, we strongly recommend that all Mahara administrators upgrade to the latest version.