Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-1000155

Опубликовано: 03 нояб. 2017
Источник: debian
EPSS Низкий

Описание

Mahara 15.04 before 15.04.8 and 15.10 before 15.10.4 and 16.04 before 16.04.2 are vulnerable to profile pictures being accessed without any access control checks consequently allowing any of a user's uploaded profile pictures to be viewable by anyone, whether or not they were currently selected as the "default" or used in any pages.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
mahararemovedpackage

EPSS

Процентиль: 38%
0.00167
Низкий

Связанные уязвимости

CVSS3: 4.3
nvd
больше 8 лет назад

Mahara 15.04 before 15.04.8 and 15.10 before 15.10.4 and 16.04 before 16.04.2 are vulnerable to profile pictures being accessed without any access control checks consequently allowing any of a user's uploaded profile pictures to be viewable by anyone, whether or not they were currently selected as the "default" or used in any pages.

CVSS3: 4.3
github
больше 3 лет назад

Mahara 15.04 before 15.04.8 and 15.10 before 15.10.4 and 16.04 before 16.04.2 are vulnerable to profile pictures being accessed without any access control checks consequently allowing any of a user's uploaded profile pictures to be viewable by anyone, whether or not they were currently selected as the "default" or used in any pages.

EPSS

Процентиль: 38%
0.00167
Низкий