CVE-2017-1000146
- EPSS 0.32%
- Veröffentlicht 03.11.2017 18:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
Mahara 1.9 before 1.9.7 and 1.10 before 1.10.5 and 15.04 before 15.04.2 are vulnerable to the arbitrary execution of Javascript in the browser of a logged-in user because the title of the portfolio page was not being properly escaped in the AJAX scri...
CVE-2017-1000147
- EPSS 0.1%
- Veröffentlicht 03.11.2017 18:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
Mahara 1.9 before 1.9.8 and 1.10 before 1.10.6 and 15.04 before 15.04.3 are vulnerable to perform a cross-site request forgery (CSRF) attack on the uploader contained in Mahara's filebrowser widget. This could allow an attacker to trick a Mahara user...
CVE-2017-1000148
- EPSS 0.51%
- Veröffentlicht 03.11.2017 18:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
Mahara 15.04 before 15.04.8 and 15.10 before 15.10.4 and 16.04 before 16.04.2 are vulnerable to PHP code execution as Mahara would pass portions of the XML through the PHP "unserialize()" function when importing a skin from an XML file.
CVE-2017-1000149
- EPSS 0.19%
- Veröffentlicht 03.11.2017 18:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
Mahara 1.10 before 1.10.9 and 15.04 before 15.04.6 and 15.10 before 15.10.2 are vulnerable to XSS due to window.opener (target="_blank" and window.open())
CVE-2017-1000150
- EPSS 0.23%
- Veröffentlicht 03.11.2017 18:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
Mahara 15.04 before 15.04.7 and 15.10 before 15.10.3 are vulnerable to prevent session IDs from being regenerated on login or logout. This makes users of the site more vulnerable to session fixation attacks.
CVE-2017-1000151
- EPSS 0.25%
- Veröffentlicht 03.11.2017 18:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
Mahara 15.04 before 15.04.9 and 15.10 before 15.10.5 and 16.04 before 16.04.3 are vulnerable to passwords or other sensitive information being passed by unusual parameters to end up in an error log.
CVE-2017-1000152
- EPSS 0.34%
- Veröffentlicht 03.11.2017 18:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
Mahara 15.04 before 15.04.7 and 15.10 before 15.10.3 running PHP 5.3 are vulnerable to one user being logged in as another user on a separate computer as the same session ID is served. This situation can occur when a user takes an action that forces ...
CVE-2017-14163
- EPSS 0.23%
- Veröffentlicht 31.10.2017 18:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
An issue was discovered in Mahara before 15.04.14, 16.x before 16.04.8, 16.10.x before 16.10.5, and 17.x before 17.04.3. When one closes the browser without logging out of Mahara, the value in the usr_session table is not removed. If someone were to ...
CVE-2017-14752
- EPSS 0.3%
- Veröffentlicht 31.10.2017 18:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
Mahara 15.04 before 15.04.15, 16.04 before 16.04.9, 16.10 before 16.10.6, and 17.04 before 17.04.4 are vulnerable to a user submitting a potential dangerous payload, e.g., XSS code, to be saved as their first name, last name, or display name in the p...
CVE-2017-15273
- EPSS 0.33%
- Veröffentlicht 31.10.2017 18:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
Mahara 15.04 before 15.04.15, 16.04 before 16.04.9, 16.10 before 16.10.6, and 17.04 before 17.04.4 are vulnerable to a user submitting a potential dangerous payload, e.g., XSS code, to be saved as titles in internal artefacts.