PT-2020-20569 · Catalyst It · Mahara
Kristina Hoeppner
+1
·
Published
2020-03-09
·
Updated
2020-03-09
·
CVE-2020-9282
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Mahara versions 18.10 through 18.10.4
Mahara versions 19.04 through 19.04.3
Mahara versions 19.10 through 19.10.1
Description
The issue allows certain personal information to be discoverable by inspecting network responses on the 'Edit access' screen when sharing portfolios.
Recommendations
For Mahara versions 18.10 through 18.10.4, update to version 18.10.5 or later.
For Mahara versions 19.04 through 19.04.3, update to version 19.04.4 or later.
For Mahara versions 19.10 through 19.10.1, update to version 19.10.2 or later.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mahara