CVE-2017-1000150
 
Severity Score
8.8
*CVSS v3
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Mahara 15.04 before 15.04.7 and 15.10 before 15.10.3 are vulnerable to prevent session IDs from being regenerated on login or logout. This makes users of the site more vulnerable to session fixation attacks.
Mahara, en versiones 15.04 anteriores a la 15.04.7 y versiones 15.10 anteriores a la 15.10.3, es vulnerable a que se evite que los ID de sesión se regeneren en el inicio o el cierre de sesión. Esto hace que los usuarios del sitio sean más vulnerables a ataques de fijación de sesión.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2017-11-02 CVE Reserved
- 2017-11-03 CVE Published
- 2024-08-05 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-384: Session Fixation
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://bugs.launchpad.net/mahara/+bug/1567784 | 2017-11-13 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Mahara Search vendor "Mahara" | Mahara Search vendor "Mahara" for product "Mahara" | 15.04 Search vendor "Mahara" for product "Mahara" and version "15.04" | rc1 |
Affected
| ||||||
Mahara Search vendor "Mahara" | Mahara Search vendor "Mahara" for product "Mahara" | 15.04 Search vendor "Mahara" for product "Mahara" and version "15.04" | rc2 |
Affected
| ||||||
Mahara Search vendor "Mahara" | Mahara Search vendor "Mahara" for product "Mahara" | 15.04.0 Search vendor "Mahara" for product "Mahara" and version "15.04.0" | - |
Affected
| ||||||
Mahara Search vendor "Mahara" | Mahara Search vendor "Mahara" for product "Mahara" | 15.04.1 Search vendor "Mahara" for product "Mahara" and version "15.04.1" | - |
Affected
| ||||||
Mahara Search vendor "Mahara" | Mahara Search vendor "Mahara" for product "Mahara" | 15.04.2 Search vendor "Mahara" for product "Mahara" and version "15.04.2" | - |
Affected
| ||||||
Mahara Search vendor "Mahara" | Mahara Search vendor "Mahara" for product "Mahara" | 15.04.3 Search vendor "Mahara" for product "Mahara" and version "15.04.3" | - |
Affected
| ||||||
Mahara Search vendor "Mahara" | Mahara Search vendor "Mahara" for product "Mahara" | 15.04.4 Search vendor "Mahara" for product "Mahara" and version "15.04.4" | - |
Affected
| ||||||
Mahara Search vendor "Mahara" | Mahara Search vendor "Mahara" for product "Mahara" | 15.04.5 Search vendor "Mahara" for product "Mahara" and version "15.04.5" | - |
Affected
| ||||||
Mahara Search vendor "Mahara" | Mahara Search vendor "Mahara" for product "Mahara" | 15.04.6 Search vendor "Mahara" for product "Mahara" and version "15.04.6" | - |
Affected
| ||||||
Mahara Search vendor "Mahara" | Mahara Search vendor "Mahara" for product "Mahara" | 15.10.0 Search vendor "Mahara" for product "Mahara" and version "15.10.0" | - |
Affected
| ||||||
Mahara Search vendor "Mahara" | Mahara Search vendor "Mahara" for product "Mahara" | 15.10.1 Search vendor "Mahara" for product "Mahara" and version "15.10.1" | - |
Affected
| ||||||
Mahara Search vendor "Mahara" | Mahara Search vendor "Mahara" for product "Mahara" | 15.10.2 Search vendor "Mahara" for product "Mahara" and version "15.10.2" | - |
Affected
|