Back to Database
Status published
Medium
CVE-2009-3298
Mahara before 1.0.13, and 1.1.x before 1.1.7, allows remote authenticated...
Vulnerability Description
Mahara before 1.0.13, and 1.1.x before 1.1.7, allows remote authenticated institution administrators to reset a site administrator password via unspecified vectors.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2009-3298
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.osvdb.org/59584
- http://www.vupen.com/english/advisories/2009/3101
- http://secunia.com/advisories/37218
- http://eduforge.org/frs/shownotes.php?release_id=546
- http://eduforge.org/frs/shownotes.php?release_id=547
- http://secunia.com/advisories/37217
- http://mahara.org/interaction/forum/topic.php?id=1169
- http://www.debian.org/security/2009/dsa-1924
- http://www.securityfocus.com/bid/36893
More from mahara
View All →CVE-2022-45134
Mahara 21.10 before 21.10.6, 22.04 before 22.04.4, and 22.10 before...
Unknown
0
CVE-2022-45133
Mahara 21.10 before 21.10.6, 22.04 before 22.04.4, and 22.10 before...
Unknown
0
CVE-2022-44544
Mahara 21.04 before 21.04.7, 21.10 before 21.10.5, 22.04 before 22.04.3,...
Unknown
0
CVE-2022-42707
In Mahara 21.04 before 21.04.7, 21.10 before 21.10.5, 22.04 before...
Unknown
0
CVE-2022-33913
In Mahara 21.04 before 21.04.6, 21.10 before 21.10.4, and 22.04.2,...
High
7.5
Affected Vendor
mahara
View all reports →Affected Software
mahara
Vulnerable Versions:
0, 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4, 1.0.5, 1.0.6, 1.0.7, 1.0.8, 1.0.10, 1.0.11, 1.1.0, 1.1.1, 1.1.2, 1.1.3, 1.1.4, 1.1.5, 1.1.6
Timeline
Official Publish:
November 3rd, 2009
Last Modified:
September 16th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.