Group Configuration Page Edit Vulnerability

Group Configuration Page Edit Vulnerability

CVE-2017-1000156 · MEDIUM Severity

AV:N/AC:L/AU:S/C:P/I:P/A:N

Mahara 15.04 before 15.04.9 and 15.10 before 15.10.5 and 16.04 before 16.04.3 are vulnerable to a group's configuration page being editable by any group member even when they didn't have the admin role.

Learn more about our Web Application Penetration Testing UK.