ZeroHour

CVE-2020-9387

CVSS 3.1
4.3 medium
EPSS
<1%p52
Published
()
Modified
Description

In Mahara 19.04 before 19.04.5 and 19.10 before 19.10.3, account details are shared in the Elasticsearch results for accounts that are not accessible when the config setting 'Isolated institutions' is turned on.

Vendors
mahara
Products
mahara
Weakness
CWE-200
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.