CVE-2018-11195
Dashboard / Vulnerabilities / CVE-2018-11195
CVE-2018-11195
Published: 1 Jun 2018Last Modified: 8 Jul 2026
Summary:
Details: Mahara 17.04 before 17.04.8 and 17.10 before 17.10.5 and 18.04 before 18.04.1 are vulnerable to the browser "back and refresh" attack. This allows malicious users with physical access to the web browser of a Mahara user, after they have logged in, to potentially gain access to their Mahara credentials.
References: https://mahara.org/interaction/forum/topic.php?id=8269, https://bugs.launchpad.net/mahara/+bug/1770561
Affected packages
Package
Name:
Purl:
Affected ranges
Type: GIT
Events:
Introduced- c1b8e4e448228b12a674c205a7288389613271e7
Affected versions
18.04.0
18.04.0_RELEASE
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
