CVE-2013-4429: Medium severity Mahara Mahara vulnerability
Mahara before 1.5.12, 1.6.x before 1.6.7, and 1.7.x before 1.7.3 does not properly restrict access to artefacts, which allows remote authenticated users to read arbitrary artefacts via the (1) artefact id in an upload action when creating a journal or (2) instconfartefactidselected[ID] parameter in an upload action when editing a block.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-4429?
The severity of CVE-2013-4429 has been classified as medium due to its potential impact on unauthorized access to artefacts.
How do I fix CVE-2013-4429?
To fix CVE-2013-4429, upgrade to Mahara version 1.5.12, 1.6.7, or 1.7.3 or later.
What versions are affected by CVE-2013-4429?
CVE-2013-4429 affects Mahara versions prior to 1.5.12, 1.6.x before 1.6.7, and 1.7.x before 1.7.3.
What types of access does CVE-2013-4429 allow?
CVE-2013-4429 allows remote authenticated users to read arbitrary artefacts due to insufficient restrictions.
What is the nature of the vulnerability in CVE-2013-4429?
The vulnerability in CVE-2013-4429 is related to improper access control, allowing exposure of sensitive artefacts.