PT-2019-19811 · Catalyst It · Mahara
Robert Lyon
·
Published
2019-05-07
·
Updated
2020-08-24
·
CVE-2019-9708
CVSS v3.1
4.9
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Mahara versions 17.10 through 17.10.7
Mahara versions 18.04 through 18.04.3
Mahara versions 18.10 through 18.10.0
Description
An issue was discovered that allows a site administrator to suspend the system user, causing all users to be locked out from the system.
Recommendations
For Mahara versions 17.10 through 17.10.7, update to version 17.10.8 or later.
For Mahara versions 18.04 through 18.04.3, update to version 18.04.4 or later.
For Mahara versions 18.10 through 18.10.0, update to version 18.10.1 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mahara