In Mahara 19.04 before 19.04.6, 19.10 before 19.10.4, and 20.04 before 20.04.1, certain places could execute file or folder names containing JavaScript.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://bugs.launchpad.net/mahara/+bug/1888163 | third party advisory patch |
https://mahara.org/interaction/forum/topic.php?id=8668 | vendor advisory |