In Mahara 19.04 before 19.04.5 and 19.10 before 19.10.3, account details are shared in the Elasticsearch results for accounts that are not accessible when the config setting 'Isolated institutions' is turned on.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2020-04-30T12:46:59
Updated: 2024-08-04T10:26:16.085Z
Reserved: 2020-02-25T00:00:00
Link: CVE-2020-9387
Vulnrichment
No data.
NVD
Status : Modified
Published: 2020-04-30T13:15:13.460
Modified: 2024-11-21T05:40:32.317
Link: CVE-2020-9387
Redhat
No data.