Mahara 15.04 before 15.04.14 and 16.04 before 16.04.8 and 16.10 before 16.10.5 and 17.04 before 17.04.3 are vulnerable to a user submitting potential dangerous payload, e.g. XSS code, to be saved as their name in the usr_registration table. The values are then emailed to the the user and administrator and if accepted become part of the new user's account.
2017-09-25T16:29:00.507
2025-04-20T01:37:25.860
Deferred
CVSSv3.0: 6.1 (MEDIUM)
AV:N/AC:M/Au:N/C:N/I:P/A:N
8.6
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | mahara | mahara | 15.04 | Yes |
Application | mahara | mahara | 15.04 | Yes |
Application | mahara | mahara | 15.04.0 | Yes |
Application | mahara | mahara | 15.04.1 | Yes |
Application | mahara | mahara | 15.04.2 | Yes |
Application | mahara | mahara | 15.04.3 | Yes |
Application | mahara | mahara | 15.04.4 | Yes |
Application | mahara | mahara | 15.04.5 | Yes |
Application | mahara | mahara | 15.04.6 | Yes |
Application | mahara | mahara | 15.04.7 | Yes |
Application | mahara | mahara | 15.04.8 | Yes |
Application | mahara | mahara | 15.04.9 | Yes |
Application | mahara | mahara | 15.04.10 | Yes |
Application | mahara | mahara | 15.04.11 | Yes |
Application | mahara | mahara | 15.04.12 | Yes |
Application | mahara | mahara | 15.04.13 | Yes |
Application | mahara | mahara | 16.04 | Yes |
Application | mahara | mahara | 16.04 | Yes |
Application | mahara | mahara | 16.04.0 | Yes |
Application | mahara | mahara | 16.04.1 | Yes |
Application | mahara | mahara | 16.04.2 | Yes |
Application | mahara | mahara | 16.04.3 | Yes |
Application | mahara | mahara | 16.04.4 | Yes |
Application | mahara | mahara | 16.04.5 | Yes |
Application | mahara | mahara | 16.04.6 | Yes |
Application | mahara | mahara | 16.04.7 | Yes |
Application | mahara | mahara | 16.10 | Yes |
Application | mahara | mahara | 16.10 | Yes |
Application | mahara | mahara | 16.10.0 | Yes |
Application | mahara | mahara | 16.10.1 | Yes |
Application | mahara | mahara | 16.10.2 | Yes |
Application | mahara | mahara | 16.10.3 | Yes |
Application | mahara | mahara | 16.10.4 | Yes |
Application | mahara | mahara | 17.04 | Yes |
Application | mahara | mahara | 17.04 | Yes |
Application | mahara | mahara | 17.04.0 | Yes |
Application | mahara | mahara | 17.04.1 | Yes |
Application | mahara | mahara | 17.04.2 | Yes |