CVE-2017-14163: High severity mahara vulnerability
An issue was discovered in Mahara before 15.04.14, 16.x before 16.04.8, 16.10.x before 16.10.5, and 17.x before 17.04.3. When one closes the browser without logging out of Mahara, the value in the usrsession table is not removed. If someone were to open a browser, visit the Mahara site, and adjust the 'mahara' cookie to the old value, they can get access to the user's account.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-14163?
CVE-2017-14163 has a medium severity rating due to its potential for unauthorized access.
How do I fix CVE-2017-14163?
To fix CVE-2017-14163, update Mahara to versions 15.04.14, 16.04.8, 16.10.5, or 17.04.3 or later.
What versions of Mahara are affected by CVE-2017-14163?
CVE-2017-14163 affects Mahara versions prior to 15.04.14, 16.x before 16.04.8, 16.10.x before 16.10.5, and 17.x before 17.04.3.
What is the nature of the vulnerability in CVE-2017-14163?
CVE-2017-14163 is a session management flaw where user session data is not cleared after a browser is closed.
What impact does CVE-2017-14163 have on system security?
CVE-2017-14163 can allow an attacker to hijack active sessions of logged-in users if they access the same browser.