CVE-2017-1000136: Mahara
Medium severity, CVSS 6.5. EPSS: 0.9% chance of exploitation in the next 30 days.
Mahara 1.8 before 1.8.6 and 1.9 before 1.9.4 and 1.10 before 1.10.1 and 15.04 before 15.04.0 are vulnerable to old sessions not being invalidated after a password change.
Affected products
- Mahara Mahara: version 1.8 only; version 1.8.0 only; version 1.8.1 only; version 1.8.2 only; version 1.8.3 only; version 1.8.4 only; …
Published 2017-11-03. Last modified 2026-06-17.