CVE-2020-9387

In Mahara 19.04 before 19.04.5 and 19.10 before 19.10.3, account details are shared in the Elasticsearch results for accounts that are not accessible when the config setting 'Isolated institutions' is turned on.
Configurations

Configuration 1

cpe:2.3:a:mahara:mahara:*:*:*:*:*:*:*:*
cpe:2.3:a:mahara:mahara:*:*:*:*:*:*:*:*
cpe:2.3:a:mahara:mahara:20.04:rc2:*:*:*:*:*:*
cpe:2.3:a:mahara:mahara:20.04:rc1:*:*:*:*:*:*

Information

Published : 2020-04-30 01:15

Updated : 2020-05-12 04:03


NVD link : CVE-2020-9387

Mitre link : CVE-2020-9387

Products Affected
No products.
CWE