CVE-2017-1000156: Mahara

Medium severity, CVSS 6.5. EPSS: 0.8% chance of exploitation in the next 30 days.

Mahara 15.04 before 15.04.9 and 15.10 before 15.10.5 and 16.04 before 16.04.3 are vulnerable to a group's configuration page being editable by any group member even when they didn't have the admin role.

Affected products

  • Mahara Mahara: version 15.04 only; version 15.04.0 only; version 15.04.1 only; version 15.04.2 only; version 15.04.3 only; version 15.04.4 only; …

Published 2017-11-03. Last modified 2026-06-17.