Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2017-11-03 CVE-2017-14359 Cross-site Scripting vulnerability in HP Performance Center 12.20
A potential security vulnerability has been identified in HPE Performance Center versions 12.20.
network
low complexity
hp CWE-79
5.4
2017-11-03 CVE-2017-1000157 Information Exposure vulnerability in Mahara
Mahara 15.04 before 15.04.13 and 16.04 before 16.04.7 and 16.10 before 16.10.4 and 17.04 before 17.04.2 are vulnerable to recording plain text passwords in the event_log table during the user creation process if full event logging was turned on.
network
high complexity
mahara CWE-200
4.4
2017-11-03 CVE-2017-1000156 Improper Privilege Management vulnerability in Mahara
Mahara 15.04 before 15.04.9 and 15.10 before 15.10.5 and 16.04 before 16.04.3 are vulnerable to a group's configuration page being editable by any group member even when they didn't have the admin role.
network
low complexity
mahara CWE-269
6.5
2017-11-03 CVE-2017-1000155 Information Exposure vulnerability in Mahara
Mahara 15.04 before 15.04.8 and 15.10 before 15.10.4 and 16.04 before 16.04.2 are vulnerable to profile pictures being accessed without any access control checks consequently allowing any of a user's uploaded profile pictures to be viewable by anyone, whether or not they were currently selected as the "default" or used in any pages.
network
low complexity
mahara CWE-200
4.3
2017-11-03 CVE-2017-1000149 Cross-site Scripting vulnerability in Mahara
Mahara 1.10 before 1.10.9 and 15.04 before 15.04.6 and 15.10 before 15.10.2 are vulnerable to XSS due to window.opener (target="_blank" and window.open())
network
low complexity
mahara CWE-79
5.4
2017-11-03 CVE-2017-1000147 Cross-Site Request Forgery (CSRF) vulnerability in Mahara
Mahara 1.9 before 1.9.8 and 1.10 before 1.10.6 and 15.04 before 15.04.3 are vulnerable to perform a cross-site request forgery (CSRF) attack on the uploader contained in Mahara's filebrowser widget.
network
low complexity
mahara CWE-352
6.8
2017-11-03 CVE-2017-1000146 Cross-site Scripting vulnerability in Mahara
Mahara 1.9 before 1.9.7 and 1.10 before 1.10.5 and 15.04 before 15.04.2 are vulnerable to the arbitrary execution of Javascript in the browser of a logged-in user because the title of the portfolio page was not being properly escaped in the AJAX script that updates the Add/remove watchlist link on artefact detail pages.
network
low complexity
mahara CWE-79
5.4
2017-11-03 CVE-2017-1000145 Unspecified vulnerability in Mahara
Mahara 1.9 before 1.9.7 and 1.10 before 1.10.5 and 15.04 before 15.04.2 are vulnerable to anonymous comments being able to be placed on artefact detail pages even when the site administrator had disallowed anonymous comments.
network
low complexity
mahara
4.9
2017-11-03 CVE-2017-1000144 Cross-site Scripting vulnerability in Mahara
Mahara 1.9 before 1.9.6 and 1.10 before 1.10.4 and 15.04 before 15.04.1 are vulnerable to a site admin or institution admin being able to place HTML and Javascript into an institution display name, which will be displayed to other users unescaped on some Mahara system pages.
network
low complexity
mahara CWE-79
4.8
2017-11-03 CVE-2017-1000143 Information Exposure vulnerability in Mahara
Mahara 1.8 before 1.8.7 and 1.9 before 1.9.5 and 1.10 before 1.10.3 and 15.04 before 15.04.0 are vulnerable to users receiving watchlist notifications about pages they do not have access to anymore.
network
low complexity
mahara CWE-200
4.3