CVE-2017-17455: Mahara
Medium severity, CVSS 5.9. EPSS: 0.6% chance of exploitation in the next 30 days.
Mahara 16.10 before 16.10.7, 17.04 before 17.04.5, and 17.10 before 17.10.2 are vulnerable to being forced, via a man-in-the-middle attack, to interact with Mahara on the HTTP protocol rather than HTTPS even when an SSL certificate is present.
Affected products
- Mahara Mahara: from 16.10.0, before 16.10.7 (fixed in 16.10.7); from 17.04.0, before 17.04.5 (fixed in 17.04.5); from 17.10.0, before 17.10.2 (fixed in 17.10.2)
Published 2018-02-20. Last modified 2026-06-17.