Mahara

Mahara

108 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.51%
  • Veröffentlicht 03.11.2017 18:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Mahara 15.04 before 15.04.8 and 15.10 before 15.10.4 and 16.04 before 16.04.2 are vulnerable to PHP code execution as Mahara would pass portions of the XML through the PHP "unserialize()" function when importing a skin from an XML file.

Exploit
  • EPSS 0.19%
  • Veröffentlicht 03.11.2017 18:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Mahara 1.10 before 1.10.9 and 15.04 before 15.04.6 and 15.10 before 15.10.2 are vulnerable to XSS due to window.opener (target="_blank" and window.open())

  • EPSS 0.23%
  • Veröffentlicht 03.11.2017 18:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Mahara 15.04 before 15.04.7 and 15.10 before 15.10.3 are vulnerable to prevent session IDs from being regenerated on login or logout. This makes users of the site more vulnerable to session fixation attacks.

  • EPSS 0.25%
  • Veröffentlicht 03.11.2017 18:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Mahara 15.04 before 15.04.9 and 15.10 before 15.10.5 and 16.04 before 16.04.3 are vulnerable to passwords or other sensitive information being passed by unusual parameters to end up in an error log.

  • EPSS 0.34%
  • Veröffentlicht 03.11.2017 18:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Mahara 15.04 before 15.04.7 and 15.10 before 15.10.3 running PHP 5.3 are vulnerable to one user being logged in as another user on a separate computer as the same session ID is served. This situation can occur when a user takes an action that forces ...

  • EPSS 0.23%
  • Veröffentlicht 31.10.2017 18:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

An issue was discovered in Mahara before 15.04.14, 16.x before 16.04.8, 16.10.x before 16.10.5, and 17.x before 17.04.3. When one closes the browser without logging out of Mahara, the value in the usr_session table is not removed. If someone were to ...

  • EPSS 0.3%
  • Veröffentlicht 31.10.2017 18:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Mahara 15.04 before 15.04.15, 16.04 before 16.04.9, 16.10 before 16.10.6, and 17.04 before 17.04.4 are vulnerable to a user submitting a potential dangerous payload, e.g., XSS code, to be saved as their first name, last name, or display name in the p...

  • EPSS 0.33%
  • Veröffentlicht 31.10.2017 18:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Mahara 15.04 before 15.04.15, 16.04 before 16.04.9, 16.10 before 16.10.6, and 17.04 before 17.04.4 are vulnerable to a user submitting a potential dangerous payload, e.g., XSS code, to be saved as titles in internal artefacts.

  • EPSS 0.28%
  • Veröffentlicht 25.09.2017 16:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Mahara 15.04 before 15.04.14 and 16.04 before 16.04.8 and 16.10 before 16.10.5 and 17.04 before 17.04.3 are vulnerable to a user submitting potential dangerous payload, e.g. XSS code, to be saved as their name in the usr_registration table. The value...

  • EPSS 0.25%
  • Veröffentlicht 19.05.2014 14:55:08
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Mahara before 1.5.12, 1.6.x before 1.6.7, and 1.7.x before 1.7.3 does not properly restrict access to artefacts, which allows remote authenticated users to read arbitrary artefacts via the (1) artefact id in an upload action when creating a journal o...