CVE-2017-1000141 describes a vulnerability in Mahara versions prior to 18.10.0 where the application improperly handled user requests related to account management. This flaw could prevent users from changing their username, primary email, or deleting their account, as it failed to prompt for a password or send a warning email as expected. Rated as medium severity (CVSS 6.5), the vulnerability is easily exploitable over the network with low attack complexity, potentially leading to low integrity and availability impacts for affected user accounts. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 18.10.0CPE matchmatch criteria | cpe:2.3:a:mahara:mahara:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.