← Back to CVE List

CVE-2017-1000152

Published: 2017-11-03T18:29Z
Last Modified: 2024-11-21T03:04Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
Mahara 15.04 before 15.04.7 and 15.10 before 15.10.3 running PHP 5.3 are vulnerable to one user being logged in as another user on a separate computer as the same session ID is served. This situation can occur when a user takes an action that forces another user to be logged out of Mahara, such as an admin changing another user's account settings. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt