Search: "mahara"

118 CVEs found

Mahara 1.9 before 1.9.7 and 1.10 before 1.10.5 and 15.04 before 15.04.2 are vulnerable to the arbitrary execution of Javascript in the browser of a logged-in user because the title of the portfolio pa...

Published: 2017-11-03
Products: 18
Vendors:
mahara

Mahara 1.9 before 1.9.8 and 1.10 before 1.10.6 and 15.04 before 15.04.3 are vulnerable to perform a cross-site request forgery (CSRF) attack on the uploader contained in Mahara's filebrowser widget. T...

Published: 2017-11-03
Products: 21
Vendors:
mahara

Mahara 15.04 before 15.04.8 and 15.10 before 15.10.4 and 16.04 before 16.04.2 are vulnerable to PHP code execution as Mahara would pass portions of the XML through the PHP "unserialize()" function whe...

Published: 2017-11-03
Products: 18
Vendors:
mahara

Mahara 1.10 before 1.10.9 and 15.04 before 15.04.6 and 15.10 before 15.10.2 are vulnerable to XSS due to window.opener (target="_blank" and window.open())

Published: 2017-11-03
Products: 22
Vendors:
mahara

Mahara 15.04 before 15.04.7 and 15.10 before 15.10.3 are vulnerable to prevent session IDs from being regenerated on login or logout. This makes users of the site more vulnerable to session fixation a...

Published: 2017-11-03
Products: 12
Vendors:
mahara

Mahara 15.04 before 15.04.9 and 15.10 before 15.10.5 and 16.04 before 16.04.3 are vulnerable to passwords or other sensitive information being passed by unusual parameters to end up in an error log.

Published: 2017-11-03
Products: 21
Vendors:
mahara
CVE-2017-1000152
9.8 CRITICAL

Mahara 15.04 before 15.04.7 and 15.10 before 15.10.3 running PHP 5.3 are vulnerable to one user being logged in as another user on a separate computer as the same session ID is served. This situation ...

Published: 2017-11-03
Products: 12
Vendors:
mahara
CVE-2017-1000153
9.8 CRITICAL

Mahara 15.04 before 15.04.10 and 15.10 before 15.10.6 and 16.04 before 16.04.4 are vulnerable to incorrect access control after the password reset link is sent via email and then user changes default ...

Published: 2017-11-03
Products: 24
Vendors:
mahara
CVE-2017-1000154
9.8 CRITICAL

Mahara 15.04 before 15.04.8 and 15.10 before 15.10.4 and 16.04 before 16.04.2 are vulnerable to some authentication methods, which do not use Mahara's built-in login form, still allowing users to log ...

Published: 2017-11-03
Products: 18
Vendors:
mahara

Mahara 15.04 before 15.04.8 and 15.10 before 15.10.4 and 16.04 before 16.04.2 are vulnerable to profile pictures being accessed without any access control checks consequently allowing any of a user's ...

Published: 2017-11-03
Products: 18
Vendors:
mahara

Mahara 15.04 before 15.04.9 and 15.10 before 15.10.5 and 16.04 before 16.04.3 are vulnerable to a group's configuration page being editable by any group member even when they didn't have the admin rol...

Published: 2017-11-03
Products: 21
Vendors:
mahara

Mahara 15.04 before 15.04.13 and 16.04 before 16.04.7 and 16.10 before 16.10.4 and 17.04 before 17.04.2 are vulnerable to recording plain text passwords in the event_log table during the user creation...

Published: 2017-11-03
Products: 34
Vendors:
mahara
CVE-2017-1000171
9.8 CRITICAL

Mahara Mobile before 1.2.1 is vulnerable to passwords being sent to the Mahara access log in plain text.

Published: 2017-11-03
Products: 1
Vendors:
mahara

An issue was discovered in Mahara before 18.10.0. It mishandled user requests that could discontinue a user's ability to maintain their own account (changing username, changing primary email address, ...

Published: 2018-01-30
Products: 1
Vendors:
mahara
CVE-2017-17454
5.4 MEDIUM

Mahara 16.10 before 16.10.7 and 17.04 before 17.04.5 and 17.10 before 17.10.2 have a Cross Site Scripting (XSS) vulnerability when a user enters invalid UTF-8 characters. These are now going to be dis...

Published: 2018-02-20
Products: 3
Vendors:
mahara
CVE-2017-17455
5.9 MEDIUM

Mahara 16.10 before 16.10.7, 17.04 before 17.04.5, and 17.10 before 17.10.2 are vulnerable to being forced, via a man-in-the-middle attack, to interact with Mahara on the HTTP protocol rather than HTT...

Published: 2018-02-20
Products: 3
Vendors:
mahara
CVE-2018-6182
6.1 MEDIUM

Mahara 16.10 before 16.10.9 and 17.04 before 17.04.7 and 17.10 before 17.10.4 are vulnerable to bad input when TinyMCE is bypassed by POST packages. Therefore, Mahara should not rely on TinyMCE's code...

Published: 2018-04-09
Products: 3
Vendors:
mahara
CVE-2018-11565
5.3 MEDIUM

Mahara 17.04 before 17.04.8 and 17.10 before 17.10.5 and 18.04 before 18.04.1 are vulnerable to mentioning the usernames that are already taken by people registered in the system rather than masking t...

Published: 2018-05-30
Products: 3
Vendors:
mahara
CVE-2018-11195
6.8 MEDIUM

Mahara 17.04 before 17.04.8 and 17.10 before 17.10.5 and 18.04 before 18.04.1 are vulnerable to the browser "back and refresh" attack. This allows malicious users with physical access to the web brows...

Published: 2018-06-01
Products: 3
Vendors:
mahara

Mahara 17.04 before 17.04.8 and 17.10 before 17.10.5 and 18.04 before 18.04.1 can be used as medium to transmit viruses by placing infected files into a Leap2A archive and uploading that to Mahara. In...

Published: 2018-06-01
Products: 3
Vendors:
mahara