CVE-2017-1000156: Medium severity mahara vulnerability
Mahara 15.04 before 15.04.9 and 15.10 before 15.10.5 and 16.04 before 16.04.3 are vulnerable to a group's configuration page being editable by any group member even when they didn't have the admin role.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2017-1000156?
CVE-2017-1000156 is a vulnerability in Mahara versions 15.04 before 15.04.9, 15.10 before 15.10.5, and 16.04 before 16.04.3 that allows group members to edit a group's configuration page even without the admin role.
How severe is CVE-2017-1000156?
CVE-2017-1000156 has a severity rating of 6.5 (medium).
How can I fix CVE-2017-1000156?
To fix CVE-2017-1000156, upgrade your Mahara installation to version 15.04.9, 15.10.5, or 16.04.3.
Where can I find more information about CVE-2017-1000156?
You can find more information about CVE-2017-1000156 at the following link: [https://bugs.launchpad.net/mahara/+bug/1609200](https://bugs.launchpad.net/mahara/+bug/1609200)
What is the CWE ID for CVE-2017-1000156?
The CWE ID for CVE-2017-1000156 is 269.