CVE-2017-1000157

CVSS 4.4 - MEDIUM
Description

Mahara 15.04 before 15.04.13 and 16.04 before 16.04.7 and 16.10 before 16.10.4 and 17.04 before 17.04.2 are vulnerable to recording plain text passwords in the event_log table during the user creation process if full event logging was turned on.

Affected Products
34
Vendor Product Version
mahara mahara 15.04
mahara mahara 15.04
mahara mahara 15.04.0
mahara mahara 15.04.1
mahara mahara 15.04.2
mahara mahara 15.04.3
mahara mahara 15.04.4
mahara mahara 15.04.5
mahara mahara 15.04.6
mahara mahara 15.04.7
mahara mahara 15.04.8
mahara mahara 15.04.9
mahara mahara 15.04.10
mahara mahara 15.04.11
mahara mahara 15.04.12
mahara mahara 16.04
mahara mahara 16.04
mahara mahara 16.04.0
mahara mahara 16.04.1
mahara mahara 16.04.2
mahara mahara 16.04.3
mahara mahara 16.04.4
mahara mahara 16.04.5
mahara mahara 16.04.6
mahara mahara 16.10
mahara mahara 16.10
mahara mahara 16.10.0
mahara mahara 16.10.1
mahara mahara 16.10.2
mahara mahara 16.10.3
mahara mahara 17.04
mahara mahara 17.04
mahara mahara 17.04.0
mahara mahara 17.04.1
Weakness Types
CWE-200
CVE Information
CVE ID:
CVE-2017-1000157
Published:
2017-11-03
Modified:
2026-05-13
CVSS Score:
4.4
Severity:
MEDIUM
Vector:
CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N
Affected Vendors
mahara
Quick Actions
CVSS Severity Scale
0.0 - 3.9 LOW
4.0 - 6.9 MEDIUM
7.0 - 8.9 HIGH
9.0 - 10.0 CRITICAL