Mahara 1.9 before 1.9.6 and 1.10 before 1.10.4 and 15.04 before 15.04.1 are vulnerable to a site admin or institution admin being able to place HTML and Javascript into an institution display name, which will be displayed to other users unescaped on some Mahara system pages.
References
Link | Resource |
---|---|
https://bugs.launchpad.net/mahara/+bug/1447377 | Exploit Issue Tracking Patch Third Party Advisory |
https://bugs.launchpad.net/mahara/+bug/1447377 | Exploit Issue Tracking Patch Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
History
21 Nov 2024, 03:04
Type | Values Removed | Values Added |
---|---|---|
References | () https://bugs.launchpad.net/mahara/+bug/1447377 - Exploit, Issue Tracking, Patch, Third Party Advisory |
Information
Published : 2017-11-03 18:29
Updated : 2024-11-21 03:04
NVD link : CVE-2017-1000144
Mitre link : CVE-2017-1000144
CVE.ORG link : CVE-2017-1000144
JSON object : View
Products Affected
mahara
- mahara
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')