Mahara

Mahara

113 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.72%
  • Veröffentlicht 30.04.2020 13:15:13
  • Zuletzt bearbeitet 21.11.2024 05:40:32

In Mahara 19.04 before 19.04.5 and 19.10 before 19.10.3, account details are shared in the Elasticsearch results for accounts that are not accessible when the config setting 'Isolated institutions' is turned on.

  • EPSS 1%
  • Veröffentlicht 09.03.2020 16:15:16
  • Zuletzt bearbeitet 21.11.2024 05:40:32

In Mahara 18.10 before 18.10.5, 19.04 before 19.04.4, and 19.10 before 19.10.2, file metadata information is disclosed to group members in the Elasticsearch result list despite them not having access to that artefact anymore.

  • EPSS 0.92%
  • Veröffentlicht 09.03.2020 14:15:11
  • Zuletzt bearbeitet 21.11.2024 05:40:21

In Mahara 18.10 before 18.10.5, 19.04 before 19.04.4, and 19.10 before 19.10.2, certain personal information is discoverable inspecting network responses on the 'Edit access' screen when sharing portfolios.

Exploit
  • EPSS 2.87%
  • Veröffentlicht 17.12.2019 18:15:12
  • Zuletzt bearbeitet 21.11.2024 01:38:44

Multiple cross-site scripting (XSS) vulnerabilities in Mahara 1.4.x before 1.4.3 and 1.5.x before 1.5.2 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) javascript innerHTML as used when generating login forms,...

  • EPSS 1.05%
  • Veröffentlicht 07.11.2019 21:15:10
  • Zuletzt bearbeitet 21.11.2024 01:49:33

Cross-site Scripting (XSS) in Mahara before 1.5.9 and 1.6.x before 1.6.4 allows remote attackers to inject arbitrary web script or HTML via the TinyMCE editor.

Exploit
  • EPSS 0.97%
  • Veröffentlicht 07.05.2019 17:29:00
  • Zuletzt bearbeitet 21.11.2024 04:52:08

An issue was discovered in Mahara 17.10 before 17.10.8, 18.04 before 18.04.4, and 18.10 before 18.10.1. A site administrator can suspend the system user (root), causing all users to be locked out from the system.

  • EPSS 0.57%
  • Veröffentlicht 07.05.2019 14:29:01
  • Zuletzt bearbeitet 21.11.2024 04:52:09

An issue was discovered in Mahara 17.10 before 17.10.8, 18.04 before 18.04.4, and 18.10 before 18.10.1. The collection title is vulnerable to Cross Site Scripting (XSS) due to not escaping it when viewing the collection's SmartEvidence overview page ...

Exploit
  • EPSS 0.52%
  • Veröffentlicht 01.06.2018 19:29:00
  • Zuletzt bearbeitet 21.11.2024 03:42:52

Mahara 17.04 before 17.04.8 and 17.10 before 17.10.5 and 18.04 before 18.04.1 are vulnerable to the browser "back and refresh" attack. This allows malicious users with physical access to the web browser of a Mahara user, after they have logged in, to...

  • EPSS 0.91%
  • Veröffentlicht 01.06.2018 19:29:00
  • Zuletzt bearbeitet 21.11.2024 03:42:52

Mahara 17.04 before 17.04.8 and 17.10 before 17.10.5 and 18.04 before 18.04.1 can be used as medium to transmit viruses by placing infected files into a Leap2A archive and uploading that to Mahara. In contrast to other ZIP files that are uploaded, Cl...

  • EPSS 0.89%
  • Veröffentlicht 30.05.2018 21:29:00
  • Zuletzt bearbeitet 21.11.2024 03:43:37

Mahara 17.04 before 17.04.8 and 17.10 before 17.10.5 and 18.04 before 18.04.1 are vulnerable to mentioning the usernames that are already taken by people registered in the system rather than masking that information.