Lucene search

K
ubuntucveUbuntu.comUB:CVE-2011-1402
HistoryMay 13, 2011 - 12:00 a.m.

CVE-2011-1402

2011-05-1300:00:00
ubuntu.com
ubuntu.com
20

CVSS2

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

EPSS

0.004

Percentile

74.4%

Mahara before 1.3.6 allows remote authenticated users to bypass intended
access restrictions, and suspend a user account, edit a view, visit a view,
edit a plan artefact, read a plans block, read a plan artefact, edit a
blog, read a blog block, read a blog artefact, or access a block, via a
request associated with (1) admin/users/search.json.php, (2)
view/newviewtoken.json.php, (3) lib/mahara.php, (4)
artefact/plans/tasks.json.php, (5) artefact/plans/viewtasks.json.php, (6)
artefact/blog/view/index.json.php, (7) artefact/blog/posts.json.php, or (8)
blocktype/myfriends/myfriends.json.php, related to incorrect privilege
enforcement, a missing user id check, and incorrect enforcement of the
Overriding Start/Stop Dates setting.

Bugs

OSVersionArchitecturePackageVersionFilename
ubuntu10.04noarchmahara< 1.2.4-1ubuntu0.3UNKNOWN
ubuntu10.10noarchmahara< 1.2.5-2ubuntu0.2UNKNOWN
ubuntu11.04noarchmahara< 1.2.7-1ubuntu0.1UNKNOWN

CVSS2

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

EPSS

0.004

Percentile

74.4%