René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

126 lines
3.9 KiB
JSON

{
"id": "CVE-2018-11195",
"sourceIdentifier": "cve@mitre.org",
"published": "2018-06-01T19:29:00.223",
"lastModified": "2019-10-03T00:03:26.223",
"vulnStatus": "Analyzed",
"descriptions": [
{
"lang": "en",
"value": "Mahara 17.04 before 17.04.8 and 17.10 before 17.10.5 and 18.04 before 18.04.1 are vulnerable to the browser \"back and refresh\" attack. This allows malicious users with physical access to the web browser of a Mahara user, after they have logged in, to potentially gain access to their Mahara credentials."
},
{
"lang": "es",
"value": "Mahara, en versiones 17.04 anteriores a la 17.04.8, versiones 17.10 anteriores a la 17.10.5 y versiones 18.04 anteriores a la 18.04.1 es vulnerable a un ataque \"back and refresh\" del navegador. Esto permite que usuarios maliciosos con acceso f\u00edsico al navegador web de un usuario de Mahara, una vez haya iniciado sesi\u00f3n, puedan obtener acceso a sus credenciales de Mahara."
}
],
"metrics": {
"cvssMetricV30": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.0",
"vectorString": "CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"attackVector": "PHYSICAL",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"availabilityImpact": "HIGH",
"baseScore": 6.8,
"baseSeverity": "MEDIUM"
},
"exploitabilityScore": 0.9,
"impactScore": 5.9
}
],
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:L/AC:L/Au:N/C:P/I:N/A:N",
"accessVector": "LOCAL",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "NONE",
"availabilityImpact": "NONE",
"baseScore": 2.1
},
"baseSeverity": "LOW",
"exploitabilityScore": 3.9,
"impactScore": 2.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-200"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:mahara:mahara:*:*:*:*:*:*:*:*",
"versionStartIncluding": "17.04.0",
"versionEndExcluding": "17.04.8",
"matchCriteriaId": "45AB0DD3-CCBA-4C94-837E-6E2B4635E8A9"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:mahara:mahara:*:*:*:*:*:*:*:*",
"versionStartIncluding": "17.10.0",
"versionEndExcluding": "17.10.5",
"matchCriteriaId": "87104E12-A6F3-4762-A518-F81C906DA755"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:mahara:mahara:18.04.0:*:*:*:*:*:*:*",
"matchCriteriaId": "50BB0028-28D9-4F5C-B46A-B5BEFA50149E"
}
]
}
]
}
],
"references": [
{
"url": "https://bugs.launchpad.net/mahara/+bug/1770561",
"source": "cve@mitre.org",
"tags": [
"Exploit",
"Vendor Advisory"
]
},
{
"url": "https://mahara.org/interaction/forum/topic.php?id=8269",
"source": "cve@mitre.org",
"tags": [
"Vendor Advisory"
]
}
]
}