CVE-2009-2171: Medium severity Mahara Mahara vulnerability
Published Jun 23, 2009
·Updated
Mahara 1.1 before 1.1.5 does not apply permission checks when saving a view that contains artefacts, which allows remote authenticated users to read another user's artefact.
Affected Software
5 affected components
Mahara Mahara=1.1.2
Mahara Mahara=1.1
Mahara Mahara=1.1.4
Mahara Mahara=1.1.1
Mahara Mahara=1.1.3
Event History
Jun 23, 2009
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2009-2171?
CVE-2009-2171 has a medium severity rating due to improper permission checks allowing unauthorized access to user artefacts.
2
How do I fix CVE-2009-2171?
To fix CVE-2009-2171, upgrade Mahara to version 1.1.5 or later to ensure proper permission checks are enforced.
3
What software versions are affected by CVE-2009-2171?
CVE-2009-2171 affects Mahara versions 1.1.2 through 1.1.4 and version 1.1.1.
4
Can remote untrusted users exploit CVE-2009-2171?
No, CVE-2009-2171 requires remote authenticated users to exploit the vulnerability and access artefacts.
5
What type of vulnerability is CVE-2009-2171?
CVE-2009-2171 is an authorization issue related to inadequate permission checks in Mahara.