CVE-2010-1670 Information
Feb 14, 2021
cve
Description
Mahara before 1.0.15 1.1.x before 1.1.9 and 1.2.x before 1.2.5 has improper configuration options for authentication plugins associated with logins that use the single sign-on (SSO) functionality which allows remote attackers to bypass authentication via an empty password. NOTE: some of these details are obtained from third party information.
Reference
http://secunia.com/advisories/40431 http://wiki.mahara.org/Release_Notes/1.0.15 http://wiki.mahara.org/Release_Notes/1.1.9 http://wiki.mahara.org/Release_Notes/1.2.5 http://www.securityfocus.com/bid/41319
Share on: