|Date: (C)2017-11-07 (M)2017-11-14|
|CVSS Score: 3.5||Access Vector: NETWORK|
|Exploitability Subscore: 6.8||Access Complexity: MEDIUM|
|Impact Subscore: 2.9||Authentication: SINGLE_INSTANCE|
| ||Confidentiality: PARTIAL|
| ||Integrity: NONE|
| ||Availability: NONE|
Mahara 15.04 before 15.04.13 and 16.04 before 16.04.7 and 16.10 before 16.10.4 and 17.04 before 17.04.2 are vulnerable to recording plain text passwords in the event_log table during the user creation process if full event logging was turned on.