296,854
Total vulnerabilities in the database
The "Reply to message" feature in Mahara 1.3.x and 1.4.x before 1.4.1 allows remote authenticated users to read the messages of a different user via a modified replyto parameter.
| Software | From | Fixed in |
|---|---|---|
| mahara / mahara | 1.3.2 | 1.3.2.x |
| mahara / mahara | 1.4-rc2 | 1.4-rc2.x |
| mahara / mahara | 1.4.0 | 1.4.0.x |
| mahara / mahara | 1.3.0-beta1 | 1.3.0-beta1.x |
| mahara / mahara | 1.3.0-rc1 | 1.3.0-rc1.x |
| mahara / mahara | 1.3.7 | 1.3.7.x |
| mahara / mahara | 1.4-rc4 | 1.4-rc4.x |
| mahara / mahara | 1.3.0 | 1.3.0.x |
| mahara / mahara | 1.4-rc3 | 1.4-rc3.x |
| mahara / mahara | 1.3.6 | 1.3.6.x |
| mahara / mahara | 1.3.1 | 1.3.1.x |
| mahara / mahara | 1.3.0-beta2 | 1.3.0-beta2.x |
| mahara / mahara | 1.3.5 | 1.3.5.x |
| mahara / mahara | 1.3.0-beta3 | 1.3.0-beta3.x |
| mahara / mahara | 1.4-rc1 | 1.4-rc1.x |
| mahara / mahara | 1.3.4 | 1.3.4.x |
| mahara / mahara | 1.3.3 | 1.3.3.x |
| mahara / mahara | 1.3.0-beta4 | 1.3.0-beta4.x |