Mahara

Mahara

113 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.66%
  • Veröffentlicht 03.11.2017 18:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

Mahara 1.8 before 1.8.7 and 1.9 before 1.9.5 and 1.10 before 1.10.3 and 15.04 before 15.04.0 are vulnerable to users receiving watchlist notifications about pages they do not have access to anymore.

Exploit
  • EPSS 0.5%
  • Veröffentlicht 03.11.2017 18:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

Mahara 1.9 before 1.9.6 and 1.10 before 1.10.4 and 15.04 before 15.04.1 are vulnerable to a site admin or institution admin being able to place HTML and Javascript into an institution display name, which will be displayed to other users unescaped on ...

Exploit
  • EPSS 0.7%
  • Veröffentlicht 03.11.2017 18:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

Mahara 1.9 before 1.9.7 and 1.10 before 1.10.5 and 15.04 before 15.04.2 are vulnerable to anonymous comments being able to be placed on artefact detail pages even when the site administrator had disallowed anonymous comments.

Exploit
  • EPSS 0.71%
  • Veröffentlicht 03.11.2017 18:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

Mahara 1.9 before 1.9.7 and 1.10 before 1.10.5 and 15.04 before 15.04.2 are vulnerable to the arbitrary execution of Javascript in the browser of a logged-in user because the title of the portfolio page was not being properly escaped in the AJAX scri...

Exploit
  • EPSS 0.4%
  • Veröffentlicht 03.11.2017 18:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

Mahara 1.9 before 1.9.8 and 1.10 before 1.10.6 and 15.04 before 15.04.3 are vulnerable to perform a cross-site request forgery (CSRF) attack on the uploader contained in Mahara's filebrowser widget. This could allow an attacker to trick a Mahara user...

  • EPSS 1.6%
  • Veröffentlicht 03.11.2017 18:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

Mahara 15.04 before 15.04.8 and 15.10 before 15.10.4 and 16.04 before 16.04.2 are vulnerable to PHP code execution as Mahara would pass portions of the XML through the PHP "unserialize()" function when importing a skin from an XML file.

Exploit
  • EPSS 0.5%
  • Veröffentlicht 03.11.2017 18:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

Mahara 1.10 before 1.10.9 and 15.04 before 15.04.6 and 15.10 before 15.10.2 are vulnerable to XSS due to window.opener (target="_blank" and window.open())

  • EPSS 0.85%
  • Veröffentlicht 03.11.2017 18:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

Mahara 15.04 before 15.04.7 and 15.10 before 15.10.3 are vulnerable to prevent session IDs from being regenerated on login or logout. This makes users of the site more vulnerable to session fixation attacks.

  • EPSS 1.08%
  • Veröffentlicht 03.11.2017 18:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

Mahara 15.04 before 15.04.9 and 15.10 before 15.10.5 and 16.04 before 16.04.3 are vulnerable to passwords or other sensitive information being passed by unusual parameters to end up in an error log.

  • EPSS 1.17%
  • Veröffentlicht 03.11.2017 18:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

Mahara 15.04 before 15.04.7 and 15.10 before 15.10.3 running PHP 5.3 are vulnerable to one user being logged in as another user on a separate computer as the same session ID is served. This situation can occur when a user takes an action that forces ...