← Back to team overview

mahara-contributors team mailing list archive

[Bug 1203924] [NEW] Bruteforce user enumeration vuln in password reset screen

 

*** This bug is a security vulnerability ***

Public security bug reported:

A user enumeration vulnerability means that an attacker can get a list
of legal usernames and/or email addresses from the site. A "bruteforce"
user enumeration vulnerability means that if they have a list of
potential usernames and/or email addresses, they can verify whether or
not each of them is registered with an account in the site.

The Mahara password reset page is vulnerable to this. You can simply go
in to https://mahara.org/forgotpass.php and enter username or email
after username or email, and get a friendly response indicating whether
each one is registered with a user in the site or not.

** Affects: mahara
     Importance: Medium
         Status: Triaged


** Tags: privacy security

-- 
You received this bug notification because you are a member of Mahara
Contributors, which is subscribed to Mahara.
Matching subscriptions: Subscription for all Mahara Contrib members
https://bugs.launchpad.net/bugs/1203924

Title:
  Bruteforce user enumeration vuln in password reset screen

Status in Mahara ePortfolio:
  Triaged

Bug description:
  A user enumeration vulnerability means that an attacker can get a list
  of legal usernames and/or email addresses from the site. A
  "bruteforce" user enumeration vulnerability means that if they have a
  list of potential usernames and/or email addresses, they can verify
  whether or not each of them is registered with an account in the site.

  The Mahara password reset page is vulnerable to this. You can simply
  go in to https://mahara.org/forgotpass.php and enter username or email
  after username or email, and get a friendly response indicating
  whether each one is registered with a user in the site or not.

To manage notifications about this bug go to:
https://bugs.launchpad.net/mahara/+bug/1203924/+subscriptions


Follow ups

References