AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2017-1000152

CRITICAL · CVSS 9.8 EPSS 1.17%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2017-11-03 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2017-1000152
Severity
CRITICAL
CVSS
9.8
EPSS
1.17%

Original NVD Description

Mahara 15.04 before 15.04.7 and 15.10 before 15.10.3 running PHP 5.3 are vulnerable to one user being logged in as another user on a separate computer as the same session ID is served. This situation can occur when a user takes an action that forces another user to be logged out of Mahara, such as an admin changing another user's account settings.