CVE-2017-1000155

Mahara 15.04 before 15.04.8 and 15.10 before 15.10.4 and 16.04 before 16.04.2 are vulnerable to profile pictures being accessed without any access control checks consequently allowing any of a user's uploaded profile pictures to be viewable by anyone, whether or not they were currently selected as the "default" or used in any pages.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.3 MEDIUM
NETWORK
LOW
LOW
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 38%
VendorProductVersion
maharamahara
15.04:rc1
maharamahara
15.04:rc2
maharamahara
15.04.0
maharamahara
15.04.1
maharamahara
15.04.2
maharamahara
15.04.3
maharamahara
15.04.4
maharamahara
15.04.5
maharamahara
15.04.6
maharamahara
15.04.7
maharamahara
16.04:rc1
maharamahara
16.04:rc2
maharamahara
16.04.0
maharamahara
16.04.1
maharamahara
15.10.0
maharamahara
15.10.1
maharamahara
15.10.2
maharamahara
15.10.3
𝑥
= Vulnerable software versions