CVE-2018-11195: Infoleak
Mahara 17.04 before 17.04.8 and 17.10 before 17.10.5 and 18.04 before 18.04.1 are vulnerable to the browser "back and refresh" attack. This allows malicious users with physical access to the web browser of a Mahara user, after they have logged in, to potentially gain access to their Mahara credentials.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2018-11195.
What is the severity of CVE-2018-11195?
The severity of CVE-2018-11195 is medium.
How does CVE-2018-11195 affect Mahara?
CVE-2018-11195 affects Mahara versions 17.04 before 17.04.8, 17.10 before 17.10.5, and 18.04 before 18.04.1.
What is the impact of CVE-2018-11195?
CVE-2018-11195 allows malicious users with physical access to a Mahara user's web browser, after they have logged in, to potentially gain access to their Mahara credentials.
How can I fix CVE-2018-11195?
To fix CVE-2018-11195, users should update their Mahara installations to versions 17.04.8, 17.10.5, or 18.04.1.