Mahara 15.04 before 15.04.10 and 15.10 before 15.10.6 and 16.04 before 16.04.4 are vulnerable to incorrect access control after the password reset link is sent via email and then user changes default email, Mahara fails to invalidate old link.Consequently the link in email can be used to gain access to the user's account.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://bugs.launchpad.net/mahara/+bug/1577251 |
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2017-11-03T18:00:00
Updated: 2024-08-05T21:53:07.128Z
Reserved: 2017-11-02T00:00:00
Link: CVE-2017-1000153
Vulnrichment
No data.
NVD
Status : Modified
Published: 2017-11-03T18:29:01.027
Modified: 2024-11-21T03:04:17.400
Link: CVE-2017-1000153
Redhat
No data.