CVE-2017-17455

EUVD-2017-8619
Mahara 16.10 before 16.10.7, 17.04 before 17.04.5, and 17.10 before 17.10.2 are vulnerable to being forced, via a man-in-the-middle attack, to interact with Mahara on the HTTP protocol rather than HTTPS even when an SSL certificate is present.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.9 MEDIUM
NETWORK
HIGH
NONE
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 33%
Affected Products (NVD)
VendorProductVersion
maharamahara
16.10.0 ≤
𝑥
< 16.10.7
maharamahara
17.04.0 ≤
𝑥
< 17.04.5
maharamahara
17.10.0 ≤
𝑥
< 17.10.2
𝑥
= Vulnerable software versions