Mahara

Mahara

113 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.69%
  • Veröffentlicht 09.04.2018 20:29:00
  • Zuletzt bearbeitet 21.11.2024 04:10:14

Mahara 16.10 before 16.10.9 and 17.04 before 17.04.7 and 17.10 before 17.10.4 are vulnerable to bad input when TinyMCE is bypassed by POST packages. Therefore, Mahara should not rely on TinyMCE's code stripping alone but also clean input on the serve...

  • EPSS 0.69%
  • Veröffentlicht 20.02.2018 22:29:00
  • Zuletzt bearbeitet 21.11.2024 03:17:57

Mahara 16.10 before 16.10.7 and 17.04 before 17.04.5 and 17.10 before 17.10.2 have a Cross Site Scripting (XSS) vulnerability when a user enters invalid UTF-8 characters. These are now going to be discarded in Mahara along with NULL characters and in...

  • EPSS 0.61%
  • Veröffentlicht 20.02.2018 22:29:00
  • Zuletzt bearbeitet 21.11.2024 03:17:57

Mahara 16.10 before 16.10.7, 17.04 before 17.04.5, and 17.10 before 17.10.2 are vulnerable to being forced, via a man-in-the-middle attack, to interact with Mahara on the HTTP protocol rather than HTTPS even when an SSL certificate is present.

  • EPSS 0.81%
  • Veröffentlicht 30.01.2018 19:29:00
  • Zuletzt bearbeitet 21.11.2024 03:04:15

An issue was discovered in Mahara before 18.10.0. It mishandled user requests that could discontinue a user's ability to maintain their own account (changing username, changing primary email address, deleting account). The correct behavior was to eit...

Exploit
  • EPSS 1.15%
  • Veröffentlicht 03.11.2017 18:29:01
  • Zuletzt bearbeitet 13.05.2026 00:24:29

Mahara 15.04 before 15.04.10 and 15.10 before 15.10.6 and 16.04 before 16.04.4 are vulnerable to incorrect access control after the password reset link is sent via email and then user changes default email, Mahara fails to invalidate old link.Consequ...

Exploit
  • EPSS 1.33%
  • Veröffentlicht 03.11.2017 18:29:01
  • Zuletzt bearbeitet 13.05.2026 00:24:29

Mahara 15.04 before 15.04.8 and 15.10 before 15.10.4 and 16.04 before 16.04.2 are vulnerable to some authentication methods, which do not use Mahara's built-in login form, still allowing users to log in even if their institution was expired or suspen...

Exploit
  • EPSS 0.68%
  • Veröffentlicht 03.11.2017 18:29:01
  • Zuletzt bearbeitet 13.05.2026 00:24:29

Mahara 15.04 before 15.04.8 and 15.10 before 15.10.4 and 16.04 before 16.04.2 are vulnerable to profile pictures being accessed without any access control checks consequently allowing any of a user's uploaded profile pictures to be viewable by anyone...

Exploit
  • EPSS 0.83%
  • Veröffentlicht 03.11.2017 18:29:01
  • Zuletzt bearbeitet 13.05.2026 00:24:29

Mahara 15.04 before 15.04.9 and 15.10 before 15.10.5 and 16.04 before 16.04.3 are vulnerable to a group's configuration page being editable by any group member even when they didn't have the admin role.

Exploit
  • EPSS 0.7%
  • Veröffentlicht 03.11.2017 18:29:01
  • Zuletzt bearbeitet 13.05.2026 00:24:29

Mahara 15.04 before 15.04.13 and 16.04 before 16.04.7 and 16.10 before 16.10.4 and 17.04 before 17.04.2 are vulnerable to recording plain text passwords in the event_log table during the user creation process if full event logging was turned on.

Exploit
  • EPSS 0.62%
  • Veröffentlicht 03.11.2017 18:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

Mahara 15.04 before 15.04.8 and 15.10 before 15.10.4 and 16.04 before 16.04.2 are vulnerable to users staying logged in to their Mahara account even when they have been logged out of Moodle (when using MNet) as Mahara did not properly implement one o...