CVE-2011-2774: Infoleak
Published Nov 15, 2011
·Updated
The "Reply to message" feature in Mahara 1.3.x and 1.4.x before 1.4.1 allows remote authenticated users to read the messages of a different user via a modified replyto parameter.
Affected Software
18 affected components
Mahara Mahara=1.3.0
Mahara Mahara=1.3.0-beta1
Mahara Mahara=1.3.0-beta2
Mahara Mahara=1.3.0-beta3
Mahara Mahara=1.3.0-beta4
Mahara Mahara=1.3.0-rc1
Mahara Mahara=1.3.1
Mahara Mahara=1.3.2
Mahara Mahara=1.3.3
Mahara Mahara=1.3.4
Mahara Mahara=1.3.5
Mahara Mahara=1.3.6
Mahara Mahara=1.3.7
Mahara Mahara=1.4-rc1
Mahara Mahara=1.4-rc2
Mahara Mahara=1.4-rc3
Mahara Mahara=1.4-rc4
Mahara Mahara=1.4.0
Remediation
Patch Available
Patch Available
Event History
Nov 15, 2011
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-2774?
CVE-2011-2774 is classified as a medium severity vulnerability due to its ability to allow remote authenticated users to read messages of other users.
2
How do I fix CVE-2011-2774?
To fix CVE-2011-2774, upgrade to Mahara version 1.4.1 or later.
3
What type of vulnerability is CVE-2011-2774?
CVE-2011-2774 is a message reading vulnerability due to improper handling of the 'replyto' parameter.
4
Which versions of Mahara are affected by CVE-2011-2774?
CVE-2011-2774 affects Mahara versions 1.3.x and 1.4.x before 1.4.1.
5
Can unprivileged users exploit CVE-2011-2774?
No, CVE-2011-2774 can only be exploited by authenticated users.