CVE-2017-1000153: Critical severity mahara vulnerability
Mahara 15.04 before 15.04.10 and 15.10 before 15.10.6 and 16.04 before 16.04.4 are vulnerable to incorrect access control after the password reset link is sent via email and then user changes default email, Mahara fails to invalidate old link.Consequently the link in email can be used to gain access to the user's account.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2017-1000153?
CVE-2017-1000153 is a vulnerability in Mahara before versions 15.04.10, 15.10.6, and 16.04.4 that allows incorrect access control after the password reset link is sent via email.
How severe is CVE-2017-1000153?
CVE-2017-1000153 has a severity score of 9.8 (critical).
How does CVE-2017-1000153 affect Mahara?
CVE-2017-1000153 affects Mahara versions 15.04 before 15.04.10, 15.10 before 15.10.6, and 16.04 before 16.04.4.
What is the impact of CVE-2017-1000153?
The impact of CVE-2017-1000153 is that an attacker can use the compromised password reset link to gain unauthorized access.
How can CVE-2017-1000153 be fixed?
To fix CVE-2017-1000153, users should upgrade to Mahara versions 15.04.10, 15.10.6, or 16.04.4.