CVE-2018-11195
Summary
| CVE | CVE-2018-11195 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-06-01 19:29:00 UTC |
| Updated | 2019-10-03 00:03:00 UTC |
| Description | Mahara 17.04 before 17.04.8 and 17.10 before 17.10.5 and 18.04 before 18.04.1 are vulnerable to the browser "back and refresh" attack. This allows malicious users with physical access to the web browser of a Mahara user, after they have logged in, to potentially gain access to their Mahara credentials. |
Risk And Classification
Problem Types: CWE-200
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Bug #1770561 “Browser back and refresh button attack vulnerabili...” : Bugs : Mahara | CONFIRM | bugs.launchpad.net | Exploit, Vendor Advisory |
| Security Announcements - Security issue relating to disclosing information <17.04.8; <17.10.5: <18.04.1 - Mahara ePortfolio System | CONFIRM | mahara.org | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.