CVE-2013-4431
Mahara before 1.5.12, 1.6.x before 1.6.7, and 1.7.x before 1.7.3 does not properly prevent access to blocks, which allows remote authenticated users to modify arbitrary blocks via the bock id in an edit request.
Ver en NVDSeveridad
N/A
EPSS
Probabilidad de explotación (próx. 30 días): 0.0062 (0.6%)
Percentil: 70.1%
EPSS: 2026-05-06
Afecta
mahara:maharaDescripción técnica
Mahara before 1.5.12, 1.6.x before 1.6.7, and 1.7.x before 1.7.3 does not properly prevent access to blocks, which allows remote authenticated users to modify arbitrary blocks via the bock id in an edit request.
Publicada: 19/5/2014, 14:55:08
Última modificación: 6/5/2026, 22:30:45
Referencias
- http://www.openwall.com/lists/oss-security/2013/10/08/3
- http://www.openwall.com/lists/oss-security/2013/10/15/1
- http://www.openwall.com/lists/oss-security/2013/10/16/7
- https://bugs.launchpad.net/mahara/+bug/1233500
- https://mahara.org/interaction/forum/topic.php?id=5753
- http://www.openwall.com/lists/oss-security/2013/10/08/3
- http://www.openwall.com/lists/oss-security/2013/10/15/1
- http://www.openwall.com/lists/oss-security/2013/10/16/7