8.8
CVSSv3

CVE-2017-1000150

Published: 03/11/2017 Updated: 13/11/2017
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 578
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

Mahara 15.04 prior to 15.04.7 and 15.10 prior to 15.10.3 are vulnerable to prevent session IDs from being regenerated on login or logout. This makes users of the site more vulnerable to session fixation attacks.

Vulnerable Product Search on Vulmon Subscribe to Product

mahara mahara 15.04.4

mahara mahara 15.04

mahara mahara 15.04.0

mahara mahara 15.04.1

mahara mahara 15.04.2

mahara mahara 15.04.6

mahara mahara 15.04.3

mahara mahara 15.04.5

mahara mahara 15.10.0

mahara mahara 15.10.1

mahara mahara 15.10.2