Show filters
15 Total Results
Displaying 11-15 of 15
Sort by:
Attacker Value
Unknown
CVE-2017-1000146
Disclosure Date: November 03, 2017 (last updated November 26, 2024)
Mahara 1.9 before 1.9.7 and 1.10 before 1.10.5 and 15.04 before 15.04.2 are vulnerable to the arbitrary execution of Javascript in the browser of a logged-in user because the title of the portfolio page was not being properly escaped in the AJAX script that updates the Add/remove watchlist link on artefact detail pages.
0
Attacker Value
Unknown
CVE-2017-1000143
Disclosure Date: November 03, 2017 (last updated November 26, 2024)
Mahara 1.8 before 1.8.7 and 1.9 before 1.9.5 and 1.10 before 1.10.3 and 15.04 before 15.04.0 are vulnerable to users receiving watchlist notifications about pages they do not have access to anymore.
0
Attacker Value
Unknown
CVE-2017-1000134
Disclosure Date: November 03, 2017 (last updated November 26, 2024)
Mahara 1.8 before 1.8.6 and 1.9 before 1.9.4 and 1.10 before 1.10.1 and 15.04 before 15.04.0 are vulnerable because group members can lose access to the group files they uploaded if another group member changes the access permissions on them.
0
Attacker Value
Unknown
CVE-2017-1000139
Disclosure Date: November 03, 2017 (last updated November 26, 2024)
Mahara 1.8 before 1.8.7 and 1.9 before 1.9.5 and 1.10 before 1.10.3 and 15.04 before 15.04.0 are vulnerable to server-side request forgery attacks as not all processes of curl redirects are checked against a white or black list. Employing SafeCurl will prevent issues.
0
Attacker Value
Unknown
CVE-2017-1000138
Disclosure Date: November 03, 2017 (last updated November 26, 2024)
Mahara 1.10 before 1.10.0 and 15.04 before 15.04.0 are vulnerable to possible cross site scripting when dragging/dropping files into a collection if the file has Javascript code in its title.
0