CVE-2017-1000145

Mahara 1.9 before 1.9.7 and 1.10 before 1.10.5 and 15.04 before 15.04.2 are vulnerable to anonymous comments being able to be placed on artefact detail pages even when the site administrator had disallowed anonymous comments.
References
Link Resource
https://bugs.launchpad.net/mahara/+bug/1460368 Exploit Issue Tracking Patch Third Party Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mahara:mahara:1.9:rc1:*:*:*:*:*:*
cpe:2.3:a:mahara:mahara:1.9.0:*:*:*:*:*:*:*
cpe:2.3:a:mahara:mahara:1.9.1:*:*:*:*:*:*:*
cpe:2.3:a:mahara:mahara:1.9.2:*:*:*:*:*:*:*
cpe:2.3:a:mahara:mahara:1.9.3:*:*:*:*:*:*:*
cpe:2.3:a:mahara:mahara:1.9.4:*:*:*:*:*:*:*
cpe:2.3:a:mahara:mahara:1.9.5:*:*:*:*:*:*:*
cpe:2.3:a:mahara:mahara:1.9.6:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:mahara:mahara:1.10:rc1:*:*:*:*:*:*
cpe:2.3:a:mahara:mahara:1.10.0:*:*:*:*:*:*:*
cpe:2.3:a:mahara:mahara:1.10.1:*:*:*:*:*:*:*
cpe:2.3:a:mahara:mahara:1.10.2:*:*:*:*:*:*:*
cpe:2.3:a:mahara:mahara:1.10.3:*:*:*:*:*:*:*
cpe:2.3:a:mahara:mahara:1.10.4:*:*:*:*:*:*:*

Configuration 3 (hide)

OR cpe:2.3:a:mahara:mahara:15.04:rc1:*:*:*:*:*:*
cpe:2.3:a:mahara:mahara:15.04:rc2:*:*:*:*:*:*
cpe:2.3:a:mahara:mahara:15.04.0:*:*:*:*:*:*:*
cpe:2.3:a:mahara:mahara:15.04.1:*:*:*:*:*:*:*

History

No history.

Information

Published : 2017-11-03 18:29

Updated : 2023-12-10 12:15


NVD link : CVE-2017-1000145

Mitre link : CVE-2017-1000145

CVE.ORG link : CVE-2017-1000145


JSON object : View

Products Affected

mahara

  • mahara