Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2017-17455

Mahara 16.10 before 16.10.7, 17.04 before 17.04.5, and 17.10 before 17.10.2 are vulnerable to being forced, via a man-in-the-middle attack, to interact with Mahara on the HTTP protocol rather than HTTPS even when an SSL certificate is present.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 35.2%
CVSS Severity
CVSS v3 Score 5.9
CVSS v2 Score 4.3
Products affected by CVE-2017-17455
  • Mahara » Mahara » Version: 16.10.0
    cpe:2.3:a:mahara:mahara:16.10.0
  • Mahara » Mahara » Version: 16.10.1
    cpe:2.3:a:mahara:mahara:16.10.1
  • Mahara » Mahara » Version: 16.10.2
    cpe:2.3:a:mahara:mahara:16.10.2
  • Mahara » Mahara » Version: 16.10.3
    cpe:2.3:a:mahara:mahara:16.10.3
  • Mahara » Mahara » Version: 16.10.4
    cpe:2.3:a:mahara:mahara:16.10.4
  • Mahara » Mahara » Version: 16.10.5
    cpe:2.3:a:mahara:mahara:16.10.5
  • Mahara » Mahara » Version: 16.10.6
    cpe:2.3:a:mahara:mahara:16.10.6
  • Mahara » Mahara » Version: 17.04.0
    cpe:2.3:a:mahara:mahara:17.04.0
  • Mahara » Mahara » Version: 17.04.1
    cpe:2.3:a:mahara:mahara:17.04.1
  • Mahara » Mahara » Version: 17.04.2
    cpe:2.3:a:mahara:mahara:17.04.2
  • Mahara » Mahara » Version: 17.04.3
    cpe:2.3:a:mahara:mahara:17.04.3
  • Mahara » Mahara » Version: 17.04.4
    cpe:2.3:a:mahara:mahara:17.04.4
  • Mahara » Mahara » Version: 17.10.0
    cpe:2.3:a:mahara:mahara:17.10.0
  • Mahara » Mahara » Version: 17.10.1
    cpe:2.3:a:mahara:mahara:17.10.1


Contact Us

Shodan ® - All rights reserved