First published: Mon Mar 28 2011(Updated: )
Cross-site request forgery (CSRF) vulnerability in Mahara 1.2.x before 1.2.7 and 1.3.x before 1.3.4 allows remote attackers to hijack the authentication of arbitrary users for requests that delete blogs.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mahara | =1.2.0 | |
Mahara | =1.2.0-alpha1 | |
Mahara | =1.2.0-alpha2 | |
Mahara | =1.2.0-alpha3 | |
Mahara | =1.2.0-beta1 | |
Mahara | =1.2.0-beta2 | |
Mahara | =1.2.0-beta3 | |
Mahara | =1.2.0-beta4 | |
Mahara | =1.2.0-rc1 | |
Mahara | =1.2.1 | |
Mahara | =1.2.2 | |
Mahara | =1.2.3 | |
Mahara | =1.2.4 | |
Mahara | =1.2.5 | |
Mahara | =1.2.6 | |
Mahara | =1.3.0 | |
Mahara | =1.3.0-beta1 | |
Mahara | =1.3.0-beta2 | |
Mahara | =1.3.0-beta3 | |
Mahara | =1.3.0-beta4 | |
Mahara | =1.3.0-rc1 | |
Mahara | =1.3.1 | |
Mahara | =1.3.2 | |
Mahara | =1.3.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-0440 is considered a medium severity vulnerability due to its potential to allow unauthorized actions via CSRF.
To fix CVE-2011-0440, upgrade Mahara to version 1.2.7 or 1.3.4 or later.
CVE-2011-0440 affects Mahara versions 1.2.x prior to 1.2.7 and 1.3.x prior to 1.3.4.
CVE-2011-0440 allows attackers to perform cross-site request forgery (CSRF) attacks that can hijack authentication for deleting blogs.
No, CVE-2011-0440 is not exploitable in the latest versions of Mahara after implementing the necessary updates.