Mahara 15.04 before 15.04.8 and 15.10 before 15.10.4 and 16.04 before 16.04.2 are vulnerable to users staying logged in to their Mahara account even when they have been logged out of Moodle (when using MNet) as Mahara did not properly implement one of the MNet SSO API functions.
References
Link | Resource |
---|---|
https://bugs.launchpad.net/mahara/+bug/1084336 | Exploit Issue Tracking Patch Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2017-11-03T18:00:00
Updated: 2017-11-03T17:57:01
Reserved: 2017-11-02T00:00:00
Link: CVE-2017-1000131
JSON object: View
NVD Information
Status : Analyzed
Published: 2017-11-03T18:29:00.200
Modified: 2019-10-03T00:03:26.223
Link: CVE-2017-1000131
JSON object: View
Redhat Information
No data.
CWE