CVE-2011-1406: Medium severity mahara vulnerability
Mahara before 1.3.6 does not properly handle an https URL in the wwwroot configuration setting, which makes it easier for user-assisted remote attackers to obtain credentials by sniffing the network at a time when an http URL is used for a login.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2011-1406?
CVE-2011-1406 is considered to have a moderate severity level due to the potential for credential theft.
How do I fix CVE-2011-1406?
To fix CVE-2011-1406, upgrade to Mahara version 1.3.6 or later to ensure proper handling of HTTPS URLs in the wwwroot configuration.
What versions of Mahara are affected by CVE-2011-1406?
CVE-2011-1406 affects Mahara versions prior to 1.3.6, including various earlier releases.
What is the impact of CVE-2011-1406?
The impact of CVE-2011-1406 allows attackers to potentially intercept user credentials during login if an HTTP URL is used instead of HTTPS.
How can users mitigate the risks associated with CVE-2011-1406?
Users can mitigate risks by ensuring their Mahara installation is configured to use HTTPS and by updating to the latest versions that resolve this vulnerability.