Mahara 15.04 before 15.04.8 and 15.10 before 15.10.4 and 16.04 before 16.04.2 are vulnerable to profile pictures being accessed without any access control checks consequently allowing any of a user's uploaded profile pictures to be viewable by anyone, whether or not they were currently selected as the "default" or used in any pages.
Advisories
Source ID Title
EUVD EUVD EUVD-2017-1440 Mahara 15.04 before 15.04.8 and 15.10 before 15.10.4 and 16.04 before 16.04.2 are vulnerable to profile pictures being accessed without any access control checks consequently allowing any of a user's uploaded profile pictures to be viewable by anyone, whether or not they were currently selected as the "default" or used in any pages.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-05T21:53:07.145Z

Reserved: 2017-11-02T00:00:00

Link: CVE-2017-1000155

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2017-11-03T18:29:01.090

Modified: 2025-04-20T01:37:25.860

Link: CVE-2017-1000155

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.