CVE-2017-1000155 describes an access control vulnerability in Mahara versions 15.04 prior to 15.04.8, 15.10 prior to 15.10.4, and 16.04 prior to 16.04.2. This flaw allows unauthorized access to any of a user's uploaded profile pictures, regardless of whether they are currently designated as the default or used on any pages. Rated with a CVSS score of 4.3 (Medium), the vulnerability has a low attack complexity and requires low privileges for exploitation, potentially leading to information disclosure. The primary impact is the unauthorized viewing of private profile images. There is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. The vulnerability has received minimal community attention and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
15.04CPE matchmatch criteria | cpe:2.3:a:mahara:mahara:15.04:rc1:*:*:*:*:*:* | ||
15.04CPE matchmatch criteria | cpe:2.3:a:mahara:mahara:15.04:rc2:*:*:*:*:*:* | ||
15.04.0CPE matchmatch criteria | cpe:2.3:a:mahara:mahara:15.04.0:*:*:*:*:*:*:* | ||
15.04.1CPE matchmatch criteria | cpe:2.3:a:mahara:mahara:15.04.1:*:*:*:*:*:*:* | ||
15.04.2CPE matchmatch criteria | cpe:2.3:a:mahara:mahara:15.04.2:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.