CVE-2017-14163 Information
Feb 14, 2021
cve
Description
An issue was discovered in Mahara before 15.04.14 16.x before 16.04.8 16.10.x before 16.10.5 and 17.x before 17.04.3. When one closes the browser without logging out of Mahara the value in the usr_session table is not removed. If someone were to open a browser visit the Mahara site and adjust the ‘mahara’ cookie to the old value they can get access to the user’s account.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Reference
https://bugs.launchpad.net/mahara/+bug/1701978
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
8.8
Share on: