CVE-2020-9282

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
09/03/2020
Last modified:
09/03/2020

Description

In Mahara 18.10 before 18.10.5, 19.04 before 19.04.4, and 19.10 before 19.10.2, certain personal information is discoverable inspecting network responses on the 'Edit access' screen when sharing portfolios.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mahara:mahara:*:*:*:*:*:*:*:* 18.10.0 (including) 18.10.5 (excluding)
cpe:2.3:a:mahara:mahara:*:*:*:*:*:*:*:* 19.04.0 (including) 19.04.4 (excluding)
cpe:2.3:a:mahara:mahara:*:*:*:*:*:*:*:* 19.10.0 (including) 19.10.2 (excluding)