CVE-2011-1403: CSRF
Cross-site request forgery (CSRF) vulnerability in the pieforms implementation in Mahara before 1.3.6 allows remote attackers to hijack the authentication of arbitrary users for requests to any form, related to inappropriate regeneration of session keys.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2011-1403?
CVE-2011-1403 is classified as a moderate severity vulnerability that allows cross-site request forgery (CSRF) attacks.
How do I fix CVE-2011-1403?
To fix CVE-2011-1403, upgrade Mahara to version 1.3.6 or later, which addresses this vulnerability.
What type of vulnerability is CVE-2011-1403?
CVE-2011-1403 is a cross-site request forgery (CSRF) vulnerability that allows attackers to hijack user sessions.
Which versions of Mahara are affected by CVE-2011-1403?
CVE-2011-1403 affects Mahara versions prior to 1.3.6, including versions 0.9.0 through 1.3.5.
Can CVE-2011-1403 lead to unauthorized actions on behalf of users?
Yes, CVE-2011-1403 can allow remote attackers to make unauthorized actions on behalf of authenticated users.