Mahara 15.04 before 15.04.10 and 15.10 before 15.10.6 and 16.04 before 16.04.4 are vulnerable to incorrect access control after the password reset link is sent via email and then user changes default email, Mahara fails to invalidate old link.Consequently the link in email can be used to gain access to the user's account.
References
Link | Resource |
---|---|
https://bugs.launchpad.net/mahara/+bug/1577251 | Exploit Issue Tracking Patch Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Information
Published : 2017-11-03 11:29
Updated : 2019-10-02 17:03
NVD link : CVE-2017-1000153
Mitre link : CVE-2017-1000153
JSON object : View
CWE
CWE-732
Incorrect Permission Assignment for Critical Resource
Products Affected
mahara
- mahara