Page 3 of 24 results (0.002 seconds)

CVSS: 4.0EPSS: 0%CPEs: 27EXPL: 0

Mahara before 1.5.13, 1.6.x before 1.6.8, and 1.7.x before 1.7.4 does not properly restrict access to folders, which allows remote authenticated users to read arbitrary folders (1) by leveraging an active folder tab loaded before permissions were removed or (2) via the folder parameter to artefact/file/groupfiles.php. Mahara anterior a 1.5.13, 1.6.x anterior a 1.6.8 y 1.7.x anterior a 1.7.4 no restringe debidamente acceso a carpetas, lo que permite a usuarios remotos autenticados leer carpetas arbitrarias (1) mediante el aprovechamiento de una etiqueta de carpeta activa cargada antes de que los permisos fueron eliminados o (2) a través del parámetro folder hacia artefact/file/groupfiles.php. • http://www.openwall.com/lists/oss-security/2013/10/08/3 http://www.openwall.com/lists/oss-security/2013/10/15/1 http://www.openwall.com/lists/oss-security/2013/10/16/7 https://bugs.launchpad.net/mahara/+bug/1034180 https://mahara.org/interaction/forum/topic.php?id=5864 • CWE-264: Permissions, Privileges, and Access Controls •

CVSS: 5.0EPSS: 0%CPEs: 75EXPL: 0

The default configuration of the auth/saml plugin in Mahara before 1.4.2 sets the "Match username attribute to Remote username" option to false, which allows remote SAML IdP servers to spoof users of other SAML IdP servers by using the same internal username. La configuración por defecto del plugin auth/SAML en Mahara antes de v1.4.2 establece el atributo "Match Username to Remote Username" a falso, lo que permite falsificar usuarios de otros servidores a los servidores remotos SAML IdP utilizando el mismo nombre de usuario interno. • http://gitorious.org/mahara/mahara/commit/f07be6020e70fa8f53cd77fdcd63e7fd7ff8aaea http://www.debian.org/security/2012/dsa-2467 http://www.openwall.com/lists/oss-security/2012/05/11/9 http://www.openwall.com/lists/oss-security/2012/05/12/4 https://bugs.launchpad.net/mahara/+bug/932909 • CWE-16: Configuration CWE-284: Improper Access Control CWE-287: Improper Authentication •

CVSS: 6.0EPSS: 0%CPEs: 72EXPL: 0

Mahara before 1.4.1, when MNet (aka the Moodle network feature) is used, allows remote authenticated users to gain privileges via a jump to an XMLRPC target. Mahara antes de v1.4.1, cuando se usa MNet (también conocido como Moodle network), permite a usuarios autenticados ganar privilegios a través de un salto a un objetivo XMLRPC • http://mahara.org/interaction/forum/topic.php?id=4138 http://openwall.com/lists/oss-security/2011/11/04/10 http://openwall.com/lists/oss-security/2011/11/04/7 http://secunia.com/advisories/46719 http://security.debian.org/debian-security/pool/updates/main/m/mahara/mahara_1.2.6-2+squeeze3.debian.tar.gz http://www.debian.org/security/2011/dsa-2334 https://bugs.launchpad.net/mahara/+bug/884223 https://launchpad.net/mahara/+milestone/1.4.1 • CWE-264: Permissions, Privileges, and Access Controls •

CVSS: 4.0EPSS: 0%CPEs: 18EXPL: 0

The "Reply to message" feature in Mahara 1.3.x and 1.4.x before 1.4.1 allows remote authenticated users to read the messages of a different user via a modified replyto parameter. La característica "Reply to message" en Mahara v1.3.x y v1.4.x, antes de v1.4.1, permite a usuarios autenticados remotamente leer mensajes de un usuario diferente a través de un parámetro replyto modificado • http://secunia.com/advisories/46719 https://launchpad.net/bugs/798128 https://launchpad.net/mahara/+milestone/1.4.1 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVSS: 6.8EPSS: 0%CPEs: 72EXPL: 0

Cross-site request forgery (CSRF) vulnerability in Mahara before 1.4.1 allows remote attackers to hijack the authentication of administrators for requests that add a user to an institution. Vulnerabilidad de falsificación de petición en sitios cruzados (CSRF) en Mahara anterior a v1.4.1 permite a atacantes remotos secuestrar la autenticación de administradores para peticiones que añaden un usuario a "institution". • http://secunia.com/advisories/46719 http://security.debian.org/debian-security/pool/updates/main/m/mahara/mahara_1.2.6-2+squeeze3.debian.tar.gz http://www.debian.org/security/2011/dsa-2334 https://bugs.launchpad.net/mahara/+bug/800032 https://launchpad.net/mahara/+milestone/1.4.1 • CWE-352: Cross-Site Request Forgery (CSRF) •