Mahara 1.8 before 1.8.7 and 1.9 before 1.9.5 and 1.10 before 1.10.3 and 15.04 before 15.04.0 are vulnerable to users receiving watchlist notifications about pages they do not have access to anymore.
References
Link | Resource |
---|---|
https://bugs.launchpad.net/mahara/+bug/1429647 | Issue Tracking Patch Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
Information
Published : 2017-11-03 11:29
Updated : 2017-11-15 06:11
NVD link : CVE-2017-1000143
Mitre link : CVE-2017-1000143
JSON object : View
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
Products Affected
mahara
- mahara