CVE-2017-1000153

critical
Published 2017-11-03 · Modified 2026-05-13
CVSS v3
9.8
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2
7.5
VIR risk
9.8

Description

Mahara 15.04 before 15.04.10 and 15.10 before 15.10.6 and 16.04 before 16.04.4 are vulnerable to incorrect access control after the password reset link is sent via email and then user changes default email, Mahara fails to invalidate old link.Consequently the link in email can be used to gain access to the user's account.

Predictions

Exploit likelihood
97%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://bugs.launchpad.net/mahara/+bug/1577251

Application impact

VendorProductVersionsFixed
maharamahara15.04
maharamahara15.04.0
maharamahara15.04.1
maharamahara15.04.2
maharamahara15.04.3
maharamahara15.04.4
maharamahara15.04.5
maharamahara15.04.6
maharamahara15.04.7
maharamahara15.04.8
maharamahara15.04.9
maharamahara16.04
maharamahara16.04.0
maharamahara16.04.1
maharamahara16.04.2
maharamahara16.04.3
maharamahara15.10.0
maharamahara15.10.1
maharamahara15.10.2
maharamahara15.10.3
maharamahara15.10.4
maharamahara15.10.5

References

CWEs

CWE-732

Verify integrity in audit chain (admin only). AS-IS.