3.5
CVSSv2

CVE-2020-9387

Published: 30/04/2020 Updated: 12/05/2020
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 4.3 | Impact Score: 1.4 | Exploitability Score: 2.8
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:P/I:N/A:N

Vulnerability Summary

In Mahara 19.04 prior to 19.04.5 and 19.10 prior to 19.10.3, account details are shared in the Elasticsearch results for accounts that are not accessible when the config setting 'Isolated institutions' is turned on.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mahara mahara

mahara mahara 20.04