CVE-2013-4431

Publication date

2014-05-19 14:00:00

Family

redhat

State

PUBLISHED

Description

Mahara before 1.5.12, 1.6.x before 1.6.7, and 1.7.x before 1.7.3 does not properly prevent access to blocks, which allows remote authenticated users to modify arbitrary blocks via the bock id in an edit request.