Vulnerability Database

296,854

Total vulnerabilities in the database

CVE-2011-2774

The "Reply to message" feature in Mahara 1.3.x and 1.4.x before 1.4.1 allows remote authenticated users to read the messages of a different user via a modified replyto parameter.

  • Published: Nov 15, 2011
  • Updated: Apr 13, 2023
  • CVE: CVE-2011-2774
  • Severity: Low
  • Exploit:

CVSS v2:

  • Severity: Low
  • Score: 4
  • AV:N/AC:L/Au:S/C:P/I:N/A:N

CWEs:

Software From Fixed in
mahara / mahara 1.3.2 1.3.2.x
mahara / mahara 1.4-rc2 1.4-rc2.x
mahara / mahara 1.4.0 1.4.0.x
mahara / mahara 1.3.0-beta1 1.3.0-beta1.x
mahara / mahara 1.3.0-rc1 1.3.0-rc1.x
mahara / mahara 1.3.7 1.3.7.x
mahara / mahara 1.4-rc4 1.4-rc4.x
mahara / mahara 1.3.0 1.3.0.x
mahara / mahara 1.4-rc3 1.4-rc3.x
mahara / mahara 1.3.6 1.3.6.x
mahara / mahara 1.3.1 1.3.1.x
mahara / mahara 1.3.0-beta2 1.3.0-beta2.x
mahara / mahara 1.3.5 1.3.5.x
mahara / mahara 1.3.0-beta3 1.3.0-beta3.x
mahara / mahara 1.4-rc1 1.4-rc1.x
mahara / mahara 1.3.4 1.3.4.x
mahara / mahara 1.3.3 1.3.3.x
mahara / mahara 1.3.0-beta4 1.3.0-beta4.x