Mahara

Mahara

108 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.37%
  • Veröffentlicht 07.05.2019 17:29:00
  • Zuletzt bearbeitet 21.11.2024 04:52:08

An issue was discovered in Mahara 17.10 before 17.10.8, 18.04 before 18.04.4, and 18.10 before 18.10.1. A site administrator can suspend the system user (root), causing all users to be locked out from the system.

  • EPSS 0.27%
  • Veröffentlicht 07.05.2019 14:29:01
  • Zuletzt bearbeitet 21.11.2024 04:52:09

An issue was discovered in Mahara 17.10 before 17.10.8, 18.04 before 18.04.4, and 18.10 before 18.10.1. The collection title is vulnerable to Cross Site Scripting (XSS) due to not escaping it when viewing the collection's SmartEvidence overview page ...

Exploit
  • EPSS 0.12%
  • Veröffentlicht 01.06.2018 19:29:00
  • Zuletzt bearbeitet 21.11.2024 03:42:52

Mahara 17.04 before 17.04.8 and 17.10 before 17.10.5 and 18.04 before 18.04.1 are vulnerable to the browser "back and refresh" attack. This allows malicious users with physical access to the web browser of a Mahara user, after they have logged in, to...

  • EPSS 0.18%
  • Veröffentlicht 01.06.2018 19:29:00
  • Zuletzt bearbeitet 21.11.2024 03:42:52

Mahara 17.04 before 17.04.8 and 17.10 before 17.10.5 and 18.04 before 18.04.1 can be used as medium to transmit viruses by placing infected files into a Leap2A archive and uploading that to Mahara. In contrast to other ZIP files that are uploaded, Cl...

  • EPSS 0.17%
  • Veröffentlicht 30.05.2018 21:29:00
  • Zuletzt bearbeitet 21.11.2024 03:43:37

Mahara 17.04 before 17.04.8 and 17.10 before 17.10.5 and 18.04 before 18.04.1 are vulnerable to mentioning the usernames that are already taken by people registered in the system rather than masking that information.

  • EPSS 0.28%
  • Veröffentlicht 09.04.2018 20:29:00
  • Zuletzt bearbeitet 21.11.2024 04:10:14

Mahara 16.10 before 16.10.9 and 17.04 before 17.04.7 and 17.10 before 17.10.4 are vulnerable to bad input when TinyMCE is bypassed by POST packages. Therefore, Mahara should not rely on TinyMCE's code stripping alone but also clean input on the serve...

  • EPSS 0.34%
  • Veröffentlicht 20.02.2018 22:29:00
  • Zuletzt bearbeitet 21.11.2024 03:17:57

Mahara 16.10 before 16.10.7 and 17.04 before 17.04.5 and 17.10 before 17.10.2 have a Cross Site Scripting (XSS) vulnerability when a user enters invalid UTF-8 characters. These are now going to be discarded in Mahara along with NULL characters and in...

  • EPSS 0.14%
  • Veröffentlicht 20.02.2018 22:29:00
  • Zuletzt bearbeitet 21.11.2024 03:17:57

Mahara 16.10 before 16.10.7, 17.04 before 17.04.5, and 17.10 before 17.10.2 are vulnerable to being forced, via a man-in-the-middle attack, to interact with Mahara on the HTTP protocol rather than HTTPS even when an SSL certificate is present.

  • EPSS 0.21%
  • Veröffentlicht 30.01.2018 19:29:00
  • Zuletzt bearbeitet 21.11.2024 03:04:15

An issue was discovered in Mahara before 18.10.0. It mishandled user requests that could discontinue a user's ability to maintain their own account (changing username, changing primary email address, deleting account). The correct behavior was to eit...

Exploit
  • EPSS 0.38%
  • Veröffentlicht 03.11.2017 18:29:01
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Mahara 15.04 before 15.04.10 and 15.10 before 15.10.6 and 16.04 before 16.04.4 are vulnerable to incorrect access control after the password reset link is sent via email and then user changes default email, Mahara fails to invalidate old link.Consequ...