Mahara 15.04 before 15.04.15, 16.04 before 16.04.9, 16.10 before 16.10.6, and 17.04 before 17.04.4 are vulnerable to a user submitting a potential dangerous payload, e.g., XSS code, to be saved as titles in internal artefacts.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://mahara.org/interaction/forum/topic.php?id=8081 | patch vendor advisory |
https://bugs.launchpad.net/mahara/+bug/1719480 | issue tracking third party advisory patch |
https://bugs.launchpad.net/mahara/+bug/1719472 | issue tracking third party advisory patch |
https://bugs.launchpad.net/mahara/+bug/1720034 | issue tracking third party advisory patch |