Vulnerabilities > Mahara > Medium

DATE CVE VULNERABILITY TITLE RISK
2019-11-07 CVE-2013-1426 Cross-site Scripting vulnerability in Mahara
Cross-site Scripting (XSS) in Mahara before 1.5.9 and 1.6.x before 1.6.4 allows remote attackers to inject arbitrary web script or HTML via the TinyMCE editor.
network
mahara CWE-79
4.3
2019-05-07 CVE-2019-9708 Unspecified vulnerability in Mahara
An issue was discovered in Mahara 17.10 before 17.10.8, 18.04 before 18.04.4, and 18.10 before 18.10.1.
network
low complexity
mahara
4.0
2018-06-01 CVE-2018-11196 Unrestricted Upload of File with Dangerous Type vulnerability in Mahara
Mahara 17.04 before 17.04.8 and 17.10 before 17.10.5 and 18.04 before 18.04.1 can be used as medium to transmit viruses by placing infected files into a Leap2A archive and uploading that to Mahara.
network
low complexity
mahara CWE-434
5.0
2018-05-30 CVE-2018-11565 Information Exposure vulnerability in Mahara
Mahara 17.04 before 17.04.8 and 17.10 before 17.10.5 and 18.04 before 18.04.1 are vulnerable to mentioning the usernames that are already taken by people registered in the system rather than masking that information.
network
low complexity
mahara CWE-200
5.0
2018-04-09 CVE-2018-6182 Cross-site Scripting vulnerability in Mahara
Mahara 16.10 before 16.10.9 and 17.04 before 17.04.7 and 17.10 before 17.10.4 are vulnerable to bad input when TinyMCE is bypassed by POST packages.
network
mahara CWE-79
4.3
2018-02-20 CVE-2017-17455 Improper Certificate Validation vulnerability in Mahara
Mahara 16.10 before 16.10.7, 17.04 before 17.04.5, and 17.10 before 17.10.2 are vulnerable to being forced, via a man-in-the-middle attack, to interact with Mahara on the HTTP protocol rather than HTTPS even when an SSL certificate is present.
network
mahara CWE-295
4.3
2018-01-30 CVE-2017-1000141 Weak Password Recovery Mechanism for Forgotten Password vulnerability in Mahara
An issue was discovered in Mahara before 18.10.0.
network
low complexity
mahara CWE-640
6.4
2017-11-03 CVE-2017-1000171 Information Exposure Through Log Files vulnerability in Mahara Mobile 1.2.0
Mahara Mobile before 1.2.1 is vulnerable to passwords being sent to the Mahara access log in plain text.
network
low complexity
mahara CWE-532
5.0
2017-11-03 CVE-2017-1000156 Improper Privilege Management vulnerability in Mahara
Mahara 15.04 before 15.04.9 and 15.10 before 15.10.5 and 16.04 before 16.04.3 are vulnerable to a group's configuration page being editable by any group member even when they didn't have the admin role.
network
low complexity
mahara CWE-269
5.5
2017-11-03 CVE-2017-1000155 Information Exposure vulnerability in Mahara
Mahara 15.04 before 15.04.8 and 15.10 before 15.10.4 and 16.04 before 16.04.2 are vulnerable to profile pictures being accessed without any access control checks consequently allowing any of a user's uploaded profile pictures to be viewable by anyone, whether or not they were currently selected as the "default" or used in any pages.
network
low complexity
mahara CWE-200
4.0