
CVE-2017-1000147
https://notcve.org/view.php?id=CVE-2017-1000147
03 Nov 2017 — Mahara 1.9 before 1.9.8 and 1.10 before 1.10.6 and 15.04 before 15.04.3 are vulnerable to perform a cross-site request forgery (CSRF) attack on the uploader contained in Mahara's filebrowser widget. This could allow an attacker to trick a Mahara user into unknowingly uploading malicious files into their Mahara account. Mahara, en versiones 1.9 anteriores a la 1.9.8, versiones 1.10 anteriores a la 1.10.6 y versiones 15.04 anteriores a la 15.04.3, es vulnerable a que se realicen ataques Cross-Site Request For... • https://bugs.launchpad.net/mahara/+bug/1480329 • CWE-352: Cross-Site Request Forgery (CSRF) •

CVE-2017-1000148
https://notcve.org/view.php?id=CVE-2017-1000148
03 Nov 2017 — Mahara 15.04 before 15.04.8 and 15.10 before 15.10.4 and 16.04 before 16.04.2 are vulnerable to PHP code execution as Mahara would pass portions of the XML through the PHP "unserialize()" function when importing a skin from an XML file. Mahara, en versiones 15.04 anteriores a la 15.04.8, versiones 15.10 anteriores a la 15.10.4 y versiones 16.04 anteriores a la 16.04.2, es vulnerable a la ejecución de código PHP, debido a que Mahara pasaría fragmentos del código XML mediante la función PHP "unserialize()" cu... • https://bugs.launchpad.net/mahara/+bug/1508684 • CWE-502: Deserialization of Untrusted Data •

CVE-2017-1000149
https://notcve.org/view.php?id=CVE-2017-1000149
03 Nov 2017 — Mahara 1.10 before 1.10.9 and 15.04 before 15.04.6 and 15.10 before 15.10.2 are vulnerable to XSS due to window.opener (target="_blank" and window.open()) Mahara, en versiones 1.10 anteriores a la 1.10.9, versiones 15.04 anteriores a la 15.04.6 y versiones 15.10 anteriores a la 15.10.2, es vulnerable a XSS debido a window.opener (target="_blank" and window.open()) • https://bugs.launchpad.net/mahara/+bug/1558361 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2017-1000150
https://notcve.org/view.php?id=CVE-2017-1000150
03 Nov 2017 — Mahara 15.04 before 15.04.7 and 15.10 before 15.10.3 are vulnerable to prevent session IDs from being regenerated on login or logout. This makes users of the site more vulnerable to session fixation attacks. Mahara, en versiones 15.04 anteriores a la 15.04.7 y versiones 15.10 anteriores a la 15.10.3, es vulnerable a que se evite que los ID de sesión se regeneren en el inicio o el cierre de sesión. Esto hace que los usuarios del sitio sean más vulnerables a ataques de fijación de sesión. • https://bugs.launchpad.net/mahara/+bug/1567784 • CWE-384: Session Fixation •

CVE-2017-1000151
https://notcve.org/view.php?id=CVE-2017-1000151
03 Nov 2017 — Mahara 15.04 before 15.04.9 and 15.10 before 15.10.5 and 16.04 before 16.04.3 are vulnerable to passwords or other sensitive information being passed by unusual parameters to end up in an error log. Mahara, en versiones 15.04 anteriores a la 15.04.9, versiones 15.10 anteriores a la 15.10.5 y versiones 16.04 anteriores a la 16.04.3, es vulnerable a que se pasen contraseñas u otra información sensible por parámetros inusuales para que terminen en un registro de error. • https://bugs.launchpad.net/mahara/+bug/1570221 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2017-1000152
https://notcve.org/view.php?id=CVE-2017-1000152
03 Nov 2017 — Mahara 15.04 before 15.04.7 and 15.10 before 15.10.3 running PHP 5.3 are vulnerable to one user being logged in as another user on a separate computer as the same session ID is served. This situation can occur when a user takes an action that forces another user to be logged out of Mahara, such as an admin changing another user's account settings. Mahara, en versiones 15.04 anteriores a la 15.04.7 y versiones 15.10 anteriores a la 15.10.3 que ejecuten PHP 5.3, es vulnerable a que un usuario inicie sesión co... • https://bugs.launchpad.net/mahara/+bug/1570744 •

CVE-2017-1000153
https://notcve.org/view.php?id=CVE-2017-1000153
03 Nov 2017 — Mahara 15.04 before 15.04.10 and 15.10 before 15.10.6 and 16.04 before 16.04.4 are vulnerable to incorrect access control after the password reset link is sent via email and then user changes default email, Mahara fails to invalidate old link.Consequently the link in email can be used to gain access to the user's account. Mahara, en versiones 15.04 anteriores a la 15.04.10, versiones 15.10 anteriores a la 15.10.6 y versiones 16.04 anteriores a la 16.04.4, es vulnerable a un control de acceso incorrecto debi... • https://bugs.launchpad.net/mahara/+bug/1577251 • CWE-732: Incorrect Permission Assignment for Critical Resource •

CVE-2017-1000154
https://notcve.org/view.php?id=CVE-2017-1000154
03 Nov 2017 — Mahara 15.04 before 15.04.8 and 15.10 before 15.10.4 and 16.04 before 16.04.2 are vulnerable to some authentication methods, which do not use Mahara's built-in login form, still allowing users to log in even if their institution was expired or suspended. Mahara, en versiones 15.04 anteriores a la 15.04.8, versiones 15.10 anteriores a la 15.10.4 y versiones 16.04 anteriores a la 16.04.2, es vulnerable a ciertos métodos de autenticación que no utilizan los formularios de inicio de sesión integrados en Mahara,... • https://bugs.launchpad.net/mahara/+bug/1580399 • CWE-287: Improper Authentication •

CVE-2017-1000155
https://notcve.org/view.php?id=CVE-2017-1000155
03 Nov 2017 — Mahara 15.04 before 15.04.8 and 15.10 before 15.10.4 and 16.04 before 16.04.2 are vulnerable to profile pictures being accessed without any access control checks consequently allowing any of a user's uploaded profile pictures to be viewable by anyone, whether or not they were currently selected as the "default" or used in any pages. Mahara, en versiones 15.04 anteriores a la 15.04.8, versiones 15.10 anteriores a la 15.10.4 y versiones 16.04 anteriores a la 16.04.2, es vulnerable a que se acceda a fotos de p... • https://bugs.launchpad.net/mahara/+bug/1600069 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2017-1000156
https://notcve.org/view.php?id=CVE-2017-1000156
03 Nov 2017 — Mahara 15.04 before 15.04.9 and 15.10 before 15.10.5 and 16.04 before 16.04.3 are vulnerable to a group's configuration page being editable by any group member even when they didn't have the admin role. Mahara, en versiones 15.04 anteriores a la 15.04.9, versiones 15.10 anteriores a la 15.10.5 y versiones 16.04 anteriores a la 16.04.3, es vulnerable a que cualquier miembro de un grupo pueda editar la página de configuración del grupo, incluso si este no tiene el rol de administrador. • https://bugs.launchpad.net/mahara/+bug/1609200 • CWE-269: Improper Privilege Management •