CVE-2018-11565

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
30/05/2018
Last modified:
03/07/2018

Description

Mahara 17.04 before 17.04.8 and 17.10 before 17.10.5 and 18.04 before 18.04.1 are vulnerable to mentioning the usernames that are already taken by people registered in the system rather than masking that information.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mahara:mahara:*:*:*:*:*:*:*:* 17.04.0 (including) 17.04.8 (excluding)
cpe:2.3:a:mahara:mahara:*:*:*:*:*:*:*:* 17.10.0 (including) 17.10.5 (excluding)
cpe:2.3:a:mahara:mahara:18.04.0:*:*:*:*:*:*:*