Vulnerabilities > Mahara
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2020-08-07 | CVE-2020-15907 | Cross-Site Scripting vulnerability in Mahara In Mahara 19.04 before 19.04.6, 19.10 before 19.10.4, and 20.04 before 20.04.1, certain places could execute file or folder names containing JavaScript. | 4.3 |
2020-04-30 | CVE-2020-9387 | Information Exposure vulnerability in Mahara In Mahara 19.04 before 19.04.5 and 19.10 before 19.10.3, account details are shared in the Elasticsearch results for accounts that are not accessible when the config setting 'Isolated institutions' is turned on. | 3.5 |
2020-03-09 | CVE-2020-9386 | Information Exposure vulnerability in Mahara In Mahara 18.10 before 18.10.5, 19.04 before 19.04.4, and 19.10 before 19.10.2, file metadata information is disclosed to group members in the Elasticsearch result list despite them not having access to that artefact anymore. | 4.0 |
2020-03-09 | CVE-2020-9282 | Information Exposure vulnerability in Mahara In Mahara 18.10 before 18.10.5, 19.04 before 19.04.4, and 19.10 before 19.10.2, certain personal information is discoverable inspecting network responses on the 'Edit access' screen when sharing portfolios. | 4.0 |
2019-12-17 | CVE-2012-2237 | Cross-Site Scripting vulnerability in multiple products Multiple cross-site scripting (XSS) vulnerabilities in Mahara 1.4.x before 1.4.3 and 1.5.x before 1.5.2 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) javascript innerHTML as used when generating login forms, (2) links or (3) resources URLs, and (4) the Display name in a user profile. | 4.3 |
2019-11-07 | CVE-2013-1426 | Cross-Site Scripting vulnerability in Mahara Cross-site Scripting (XSS) in Mahara before 1.5.9 and 1.6.x before 1.6.4 allows remote attackers to inject arbitrary web script or HTML via the TinyMCE editor. | 4.3 |
2019-05-07 | CVE-2019-9708 | Unspecified vulnerability in Mahara An issue was discovered in Mahara 17.10 before 17.10.8, 18.04 before 18.04.4, and 18.10 before 18.10.1. | 4.0 |
2019-05-07 | CVE-2019-9709 | Cross-Site Scripting vulnerability in Mahara An issue was discovered in Mahara 17.10 before 17.10.8, 18.04 before 18.04.4, and 18.10 before 18.10.1. | 3.5 |
2018-06-01 | CVE-2018-11196 | Unrestricted Upload of File With Dangerous Type vulnerability in Mahara Mahara 17.04 before 17.04.8 and 17.10 before 17.10.5 and 18.04 before 18.04.1 can be used as medium to transmit viruses by placing infected files into a Leap2A archive and uploading that to Mahara. | 5.0 |
2018-06-01 | CVE-2018-11195 | Information Exposure vulnerability in Mahara Mahara 17.04 before 17.04.8 and 17.10 before 17.10.5 and 18.04 before 18.04.1 are vulnerable to the browser "back and refresh" attack. | 2.1 |