Vulnerabilities > Mahara > Mahara > 1.5.10

DATE CVE VULNERABILITY TITLE RISK
2022-04-28 CVE-2022-28892 Cross-Site Request Forgery (CSRF) vulnerability in Mahara
Mahara before 20.10.5, 21.04.4, 21.10.2, and 22.04.0 is vulnerable to Cross Site Request Forgery (CSRF) because randomly generated tokens are too easily guessable.
network
low complexity
mahara CWE-352
8.8
2022-04-28 CVE-2022-29584 Cross-site Scripting vulnerability in Mahara
Mahara before 20.10.5, 21.04.4, 21.10.2, and 22.04.0 allows stored XSS when a particular Cascading Style Sheets (CSS) class for embedly is used, and JavaScript code is constructed to perform an action.
network
mahara CWE-79
3.5
2022-04-28 CVE-2022-29585 Incorrect Default Permissions vulnerability in Mahara
In Mahara before 20.10.5, 21.04.4, 21.10.2, and 22.04.0, a site using Isolated Institutions is vulnerable if more than ten groups are used.
network
low complexity
mahara CWE-276
5.0
2021-11-03 CVE-2021-40848 Improper Neutralization of Formula Elements in a CSV File vulnerability in Mahara
In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, exported CSV files could contain characters that a spreadsheet program could interpret as a command, leading to execution of a malicious string locally on a device, aka CSV injection.
network
mahara CWE-1236
6.8
2021-11-03 CVE-2021-40849 Insufficient Session Expiration vulnerability in Mahara
In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, the account associated with a web services token is vulnerable to being exploited and logged into, resulting in information disclosure (at a minimum) and often escalation of privileges.
network
low complexity
mahara CWE-613
7.5
2018-01-30 CVE-2017-1000141 Weak Password Recovery Mechanism for Forgotten Password vulnerability in Mahara
An issue was discovered in Mahara before 18.10.0.
network
low complexity
mahara CWE-640
6.4
2014-05-19 CVE-2013-4432 Permissions, Privileges, and Access Controls vulnerability in Mahara
Mahara before 1.5.13, 1.6.x before 1.6.8, and 1.7.x before 1.7.4 does not properly restrict access to folders, which allows remote authenticated users to read arbitrary folders (1) by leveraging an active folder tab loaded before permissions were removed or (2) via the folder parameter to artefact/file/groupfiles.php.
network
low complexity
mahara CWE-264
4.0
2014-05-19 CVE-2013-4431 Permissions, Privileges, and Access Controls vulnerability in Mahara
Mahara before 1.5.12, 1.6.x before 1.6.7, and 1.7.x before 1.7.3 does not properly prevent access to blocks, which allows remote authenticated users to modify arbitrary blocks via the bock id in an edit request.
network
low complexity
mahara CWE-264
5.5
2014-05-19 CVE-2013-4430 Cross-Site Scripting vulnerability in Mahara
Cross-site scripting (XSS) vulnerability in Mahara before 1.5.12, 1.6.x before 1.6.7, and 1.7.x before 1.7.3 allows remote attackers to inject arbitrary web script or HTML via the Host header to lib/web.php.
network
mahara CWE-79
4.3
2014-05-19 CVE-2013-4429 Permissions, Privileges, and Access Controls vulnerability in Mahara
Mahara before 1.5.12, 1.6.x before 1.6.7, and 1.7.x before 1.7.3 does not properly restrict access to artefacts, which allows remote authenticated users to read arbitrary artefacts via the (1) artefact id in an upload action when creating a journal or (2) instconf_artefactid_selected[ID] parameter in an upload action when editing a block.
network
low complexity
mahara CWE-264
4.0