CVE-2018-11565

Source
https://nvd.nist.gov/vuln/detail/CVE-2018-11565
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2018-11565.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2018-11565
Published
2018-05-30T21:29:00Z
Modified
2025-01-08T04:56:08.038495Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
[none]
Details

Mahara 17.04 before 17.04.8 and 17.10 before 17.10.5 and 18.04 before 18.04.1 are vulnerable to mentioning the usernames that are already taken by people registered in the system rather than masking that information.

References

Affected packages

Git / github.com/maharaproject/mahara

Affected ranges

Type
GIT
Repo
https://github.com/maharaproject/mahara
Events

Affected versions

17.*

17.04.0_RELEASE
17.04.1_RELEASE
17.04.2_RELEASE
17.04.3_RELEASE
17.04.4_RELEASE
17.04.5_RELEASE
17.04.6_RELEASE
17.04.7_RELEASE