Launchpad.net

CVE 2011-2774

The "Reply to message" feature in Mahara 1.3.x and 1.4.x before 1.4.1 allows remote authenticated users to read the messages of a different user via a modified replyto parameter.

See the CVE page on Mitre.org for more details.