Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2012-6037


Multiple cross-site scripting (XSS) vulnerabilities in Mahara 1.4.x before 1.4.5 and 1.5.x before 1.5.4, and other versions including 1.2, allow remote attackers to inject arbitrary web script or HTML via a CSV header with "unknown fields," which are not properly handled in error messages in the (1) bulk user, (2) group, and (3) group member upload capabilities. NOTE: this issue was originally part of CVE-2012-2243, but that ID was SPLIT due to different issues by different researchers.


Published

2012-11-24T20:55:04.367

Last Modified

2025-04-11T00:51:21.963

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 4.3 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:N/I:P/A:N

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

8.6

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application mahara mahara 1.4 Yes
Application mahara mahara 1.4 Yes
Application mahara mahara 1.4 Yes
Application mahara mahara 1.4 Yes
Application mahara mahara 1.4.0 Yes
Application mahara mahara 1.4.1 Yes
Application mahara mahara 1.4.2 Yes
Application mahara mahara 1.4.3 Yes
Application mahara mahara 1.4.4 Yes
Application mahara mahara 1.5 Yes
Application mahara mahara 1.5 Yes
Application mahara mahara 1.5.0 Yes
Application mahara mahara 1.5.1 Yes
Application mahara mahara 1.5.2 Yes
Application mahara mahara 1.5.3 Yes

References