CVE-2011-1404: Medium severity mahara vulnerability
Mahara before 1.3.6 does not properly restrict the data in responses to AJAX calls, which allows remote authenticated users to obtain sensitive information via a request associated with (1) blocktype/myfriends/myfriends.json.php, (2) json/usersearch.php, (3) group/membersearchresults.json.php, or (4) json/friendsearch.php, as demonstrated by information about friends and e-mail addresses.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2011-1404?
CVE-2011-1404 is classified as a medium severity vulnerability.
How do I fix CVE-2011-1404?
To fix CVE-2011-1404, upgrade Mahara to version 1.3.6 or later.
What types of sensitive information can be exposed by CVE-2011-1404?
CVE-2011-1404 can allow remote authenticated users to access sensitive user data through specific AJAX calls.
Which versions of Mahara are affected by CVE-2011-1404?
CVE-2011-1404 affects Mahara versions prior to 1.3.6, including various 1.x and 0.9.x versions.
Who is impacted by CVE-2011-1404?
Remote authenticated users in Mahara installations prior to version 1.3.6 are impacted by CVE-2011-1404.