Vulnerability CVE-2018-11565


Published: 2018-05-30

Description:
Mahara 17.04 before 17.04.8 and 17.10 before 17.10.5 and 18.04 before 18.04.1 are vulnerable to mentioning the usernames that are already taken by people registered in the system rather than masking that information.

Type:

CWE-200

(Information Exposure)

CVSS2 => (AV:N/AC:L/Au:N/C:P/I:N/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
5/10
2.9/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
None
None
Affected software
Mahara -> Mahara 

 References:
https://bugs.launchpad.net/mahara/+bug/1772774
https://mahara.org/interaction/forum/topic.php?id=8271

Copyright 2024, cxsecurity.com

 

Back to Top