First published: Mon May 19 2014(Updated: )
Mahara before 1.5.12, 1.6.x before 1.6.7, and 1.7.x before 1.7.3 does not properly prevent access to blocks, which allows remote authenticated users to modify arbitrary blocks via the bock id in an edit request.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mahara | <=1.5.11 | |
Mahara | =1.5-rc1 | |
Mahara | =1.5-rc2 | |
Mahara | =1.5.0 | |
Mahara | =1.5.1 | |
Mahara | =1.5.2 | |
Mahara | =1.5.3 | |
Mahara | =1.5.4 | |
Mahara | =1.5.6 | |
Mahara | =1.5.7 | |
Mahara | =1.5.8 | |
Mahara | =1.5.9 | |
Mahara | =1.5.10 | |
Mahara | =1.7.-rc1 | |
Mahara | =1.7.0 | |
Mahara | =1.7.1 | |
Mahara | =1.7.2 | |
Mahara | =1.6.0 | |
Mahara | =1.6.1 | |
Mahara | =1.6.2 | |
Mahara | =1.6.3 | |
Mahara | =1.6.4 | |
Mahara | =1.6.5 | |
Mahara | =1.6.6 | |
<=1.5.11 | ||
=1.5-rc1 | ||
=1.5-rc2 | ||
=1.5.0 | ||
=1.5.1 | ||
=1.5.2 | ||
=1.5.3 | ||
=1.5.4 | ||
=1.5.6 | ||
=1.5.7 | ||
=1.5.8 | ||
=1.5.9 | ||
=1.5.10 | ||
=1.7.-rc1 | ||
=1.7.0 | ||
=1.7.1 | ||
=1.7.2 | ||
=1.6.0 | ||
=1.6.1 | ||
=1.6.2 | ||
=1.6.3 | ||
=1.6.4 | ||
=1.6.5 | ||
=1.6.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-4431 has a medium severity rating, indicating a potential impact on system integrity.
To fix CVE-2013-4431, upgrade Mahara to version 1.5.12, 1.6.7, or 1.7.3 or later.
CVE-2013-4431 affects users of Mahara versions prior to 1.5.12, 1.6.x before 1.6.7, and 1.7.x before 1.7.3.
CVE-2013-4431 allows remote authenticated users to modify arbitrary blocks by manipulating the block ID.
CVE-2013-4431 was disclosed on October 8, 2013.