Show filters
3 Total Results
Displaying 1-3 of 3
Sort by:
Attacker Value
Unknown
CVE-2022-29585
Disclosure Date: April 28, 2022 (last updated February 23, 2025)
In Mahara before 20.10.5, 21.04.4, 21.10.2, and 22.04.0, a site using Isolated Institutions is vulnerable if more than ten groups are used. They are all shown from page 2 of the group results list (rather than only being shown for the institution that the viewer is a member of).
0
Attacker Value
Unknown
CVE-2022-29584
Disclosure Date: April 28, 2022 (last updated February 23, 2025)
Mahara before 20.10.5, 21.04.4, 21.10.2, and 22.04.0 allows stored XSS when a particular Cascading Style Sheets (CSS) class for embedly is used, and JavaScript code is constructed to perform an action.
0
Attacker Value
Unknown
CVE-2022-28892
Disclosure Date: April 28, 2022 (last updated February 23, 2025)
Mahara before 20.10.5, 21.04.4, 21.10.2, and 22.04.0 is vulnerable to Cross Site Request Forgery (CSRF) because randomly generated tokens are too easily guessable.
0