Vulnerability: Plain Text Password Recording in Mahara Event Log

Vulnerability: Plain Text Password Recording in Mahara Event Log

CVE-2017-1000157 · LOW Severity

AV:N/AC:M/AU:S/C:P/I:N/A:N

Mahara 15.04 before 15.04.13 and 16.04 before 16.04.7 and 16.10 before 16.10.4 and 17.04 before 17.04.2 are vulnerable to recording plain text passwords in the event_log table during the user creation process if full event logging was turned on.

Learn more about our User Device Pen Test.