CyberRota Analysis
This is a high severity vulnerability with a CVSS score of 8.0. See the original NVD description below for full technical details.
CVE
CVE-2017-1000139
Severity
HIGH
CVSS
8
EPSS
0.72%
Original NVD Description
Mahara 1.8 before 1.8.7 and 1.9 before 1.9.5 and 1.10 before 1.10.3 and 15.04 before 15.04.0 are vulnerable to server-side request forgery attacks as not all processes of curl redirects are checked against a white or black list. Employing SafeCurl will prevent issues.
Related CVEs
Other vulnerabilities affecting the same vendor(s)