CVE-2012-2237
- EPSS 5.63%
- Veröffentlicht 17.12.2019 18:15:12
- Zuletzt bearbeitet 21.11.2024 01:38:44
Multiple cross-site scripting (XSS) vulnerabilities in Mahara 1.4.x before 1.4.3 and 1.5.x before 1.5.2 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) javascript innerHTML as used when generating login forms,...
CVE-2013-1426
- EPSS 0.41%
- Veröffentlicht 07.11.2019 21:15:10
- Zuletzt bearbeitet 21.11.2024 01:49:33
Cross-site Scripting (XSS) in Mahara before 1.5.9 and 1.6.x before 1.6.4 allows remote attackers to inject arbitrary web script or HTML via the TinyMCE editor.
CVE-2019-9708
- EPSS 0.37%
- Veröffentlicht 07.05.2019 17:29:00
- Zuletzt bearbeitet 21.11.2024 04:52:08
An issue was discovered in Mahara 17.10 before 17.10.8, 18.04 before 18.04.4, and 18.10 before 18.10.1. A site administrator can suspend the system user (root), causing all users to be locked out from the system.
CVE-2019-9709
- EPSS 0.27%
- Veröffentlicht 07.05.2019 14:29:01
- Zuletzt bearbeitet 21.11.2024 04:52:09
An issue was discovered in Mahara 17.10 before 17.10.8, 18.04 before 18.04.4, and 18.10 before 18.10.1. The collection title is vulnerable to Cross Site Scripting (XSS) due to not escaping it when viewing the collection's SmartEvidence overview page ...
CVE-2018-11195
- EPSS 0.05%
- Veröffentlicht 01.06.2018 19:29:00
- Zuletzt bearbeitet 21.11.2024 03:42:52
Mahara 17.04 before 17.04.8 and 17.10 before 17.10.5 and 18.04 before 18.04.1 are vulnerable to the browser "back and refresh" attack. This allows malicious users with physical access to the web browser of a Mahara user, after they have logged in, to...
CVE-2018-11196
- EPSS 0.18%
- Veröffentlicht 01.06.2018 19:29:00
- Zuletzt bearbeitet 21.11.2024 03:42:52
Mahara 17.04 before 17.04.8 and 17.10 before 17.10.5 and 18.04 before 18.04.1 can be used as medium to transmit viruses by placing infected files into a Leap2A archive and uploading that to Mahara. In contrast to other ZIP files that are uploaded, Cl...
CVE-2018-11565
- EPSS 0.17%
- Veröffentlicht 30.05.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 03:43:37
Mahara 17.04 before 17.04.8 and 17.10 before 17.10.5 and 18.04 before 18.04.1 are vulnerable to mentioning the usernames that are already taken by people registered in the system rather than masking that information.
CVE-2018-6182
- EPSS 0.28%
- Veröffentlicht 09.04.2018 20:29:00
- Zuletzt bearbeitet 21.11.2024 04:10:14
Mahara 16.10 before 16.10.9 and 17.04 before 17.04.7 and 17.10 before 17.10.4 are vulnerable to bad input when TinyMCE is bypassed by POST packages. Therefore, Mahara should not rely on TinyMCE's code stripping alone but also clean input on the serve...
CVE-2017-17454
- EPSS 0.34%
- Veröffentlicht 20.02.2018 22:29:00
- Zuletzt bearbeitet 21.11.2024 03:17:57
Mahara 16.10 before 16.10.7 and 17.04 before 17.04.5 and 17.10 before 17.10.2 have a Cross Site Scripting (XSS) vulnerability when a user enters invalid UTF-8 characters. These are now going to be discarded in Mahara along with NULL characters and in...
CVE-2017-17455
- EPSS 0.14%
- Veröffentlicht 20.02.2018 22:29:00
- Zuletzt bearbeitet 21.11.2024 03:17:57
Mahara 16.10 before 16.10.7, 17.04 before 17.04.5, and 17.10 before 17.10.2 are vulnerable to being forced, via a man-in-the-middle attack, to interact with Mahara on the HTTP protocol rather than HTTPS even when an SSL certificate is present.