Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2020-9387


In Mahara 19.04 before 19.04.5 and 19.10 before 19.10.3, account details are shared in the Elasticsearch results for accounts that are not accessible when the config setting 'Isolated institutions' is turned on.


Published

2020-04-30T13:15:13.460

Last Modified

2024-11-21T05:40:32.317

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 4.3 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:S/C:P/I:N/A:N

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: SINGLE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

6.8

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-200

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application mahara mahara < 19.04.5 Yes
Application mahara mahara < 19.10.3 Yes
Application mahara mahara 20.04 Yes
Application mahara mahara 20.04 Yes

References