CVE-2009-2171 Information

Description

Mahara 1.1 before 1.1.5 does not apply permission checks when saving a view that contains artefacts which allows remote authenticated users to read another user’s artefact.

Reference

http://mahara.org/interaction/forum/topic.php?id=753

Share on: