CVE-2017-1000152: Critical severity mahara vulnerability
Mahara 15.04 before 15.04.7 and 15.10 before 15.10.3 running PHP 5.3 are vulnerable to one user being logged in as another user on a separate computer as the same session ID is served. This situation can occur when a user takes an action that forces another user to be logged out of Mahara, such as an admin changing another user's account settings.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2017-1000152?
CVE-2017-1000152 is a vulnerability in Mahara versions 15.04 before 15.04.7 and 15.10 before 15.10.3 running PHP 5.3, which allows one user to be logged in as another user on a separate computer.
How severe is CVE-2017-1000152?
CVE-2017-1000152 has a severity rating of 9.8 (Critical).
How does CVE-2017-1000152 occur?
CVE-2017-1000152 occurs when a user takes an action that forces another user to be logged out of Mahara, allowing the first user to be logged in as the second user on a different computer.
Which versions of Mahara are affected by CVE-2017-1000152?
Mahara versions 15.04 before 15.04.7 and 15.10 before 15.10.3 running PHP 5.3 are affected by CVE-2017-1000152.
How do I fix CVE-2017-1000152?
To fix CVE-2017-1000152, upgrade to Mahara version 15.04.7 or 15.10.3 running PHP 5.4 or higher.