CVE-2018-11195

Source
https://nvd.nist.gov/vuln/detail/CVE-2018-11195
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2018-11195.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2018-11195
Published
2018-06-01T19:29:00Z
Modified
2025-01-08T04:56:35.658345Z
Severity
  • 6.8 (Medium) CVSS_V3 - CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

Mahara 17.04 before 17.04.8 and 17.10 before 17.10.5 and 18.04 before 18.04.1 are vulnerable to the browser "back and refresh" attack. This allows malicious users with physical access to the web browser of a Mahara user, after they have logged in, to potentially gain access to their Mahara credentials.

References

Affected packages

Git / github.com/maharaproject/mahara

Affected ranges

Type
GIT
Repo
https://github.com/maharaproject/mahara
Events

Affected versions

17.*

17.04.0_RELEASE
17.04.1_RELEASE
17.04.2_RELEASE
17.04.3_RELEASE
17.04.4_RELEASE
17.04.5_RELEASE
17.04.6_RELEASE
17.04.7_RELEASE