Mahara 1.4.x before 1.4.4 and 1.5.x before 1.5.3 allows remote attackers to read arbitrary files or create TCP connections via an XML external entity (XXE) injection attack, as demonstrated by reading config.php.
2012-11-24T20:55:02.087
2025-04-11T00:51:21.963
Deferred
CVSSv3.1: 9.1 (CRITICAL)
AV:N/AC:L/Au:N/C:P/I:P/A:N
10.0
4.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | mahara | mahara | < 1.4.4 | Yes |
Application | mahara | mahara | < 1.5.3 | Yes |
Operating System | debian | debian_linux | 6.0 | Yes |