CVE-2011-1406
Publication date 13 May 2011
Last updated 24 July 2024
Ubuntu priority
Description
Mahara before 1.3.6 does not properly handle an https URL in the wwwroot configuration setting, which makes it easier for user-assisted remote attackers to obtain credentials by sniffing the network at a time when an http URL is used for a login.