Vulnerability Details CVE-2020-9282
In Mahara 18.10 before 18.10.5, 19.04 before 19.04.4, and 19.10 before 19.10.2, certain personal information is discoverable inspecting network responses on the 'Edit access' screen when sharing portfolios.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 50.6%
CVSS Severity
CVSS v3 Score 6.5
CVSS v2 Score 4.0
Products affected by CVE-2020-9282
-
cpe:2.3:a:mahara:mahara:18.10.0
-
cpe:2.3:a:mahara:mahara:18.10.1
-
cpe:2.3:a:mahara:mahara:18.10.2
-
cpe:2.3:a:mahara:mahara:18.10.3
-
cpe:2.3:a:mahara:mahara:18.10.4
-
cpe:2.3:a:mahara:mahara:19.04.0
-
cpe:2.3:a:mahara:mahara:19.04.1
-
cpe:2.3:a:mahara:mahara:19.04.2
-
cpe:2.3:a:mahara:mahara:19.04.3
-
cpe:2.3:a:mahara:mahara:19.10.0
-
cpe:2.3:a:mahara:mahara:19.10.1