CVE-2018-11565
Summary
| CVE | CVE-2018-11565 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-05-30 21:29:00 UTC |
| Updated | 2018-07-03 13:53:00 UTC |
| Description | Mahara 17.04 before 17.04.8 and 17.10 before 17.10.5 and 18.04 before 18.04.1 are vulnerable to mentioning the usernames that are already taken by people registered in the system rather than masking that information. |
Risk And Classification
Problem Types: CWE-200
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Bug #1772774 “change error message when changing username” : Bugs : Mahara | CONFIRM | bugs.launchpad.net | Issue Tracking, Patch, Vendor Advisory |
| Security Announcements - Security issue relating to disclosing information <17.04.8; <17.10.5: <18.04.1 - Mahara ePortfolio System | CONFIRM | mahara.org | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.