Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
mahara mahara vulnerabilities and exploits
(subscribe to this query)
9.8
CVSSv3
CVE-2022-44544
Mahara 21.04 prior to 21.04.7, 21.10 prior to 21.10.5, 22.04 prior to 22.04.3, and 22.10 prior to 22.10.0 potentially allow a PDF export to trigger a remote shell if the site is running on Ubuntu and the flag -dSAFER is not set with Ghostscript.
Mahara Mahara 22.10.0
Mahara Mahara
9.8
CVSSv3
CVE-2021-40849
In Mahara prior to 20.04.5, 20.10.3, 21.04.2, and 21.10.0, the account associated with a web services token is vulnerable to being exploited and logged into, resulting in information disclosure (at a minimum) and often escalation of privileges.
Mahara Mahara
Mahara Mahara 21.10.0
9.8
CVSSv3
CVE-2017-1000152
Mahara 15.04 prior to 15.04.7 and 15.10 prior to 15.10.3 running PHP 5.3 are vulnerable to one user being logged in as another user on a separate computer as the same session ID is served. This situation can occur when a user takes an action that forces another user to be logged ...
Mahara Mahara 15.04
Mahara Mahara 15.04.0
Mahara Mahara 15.04.5
Mahara Mahara 15.04.1
Mahara Mahara 15.04.2
Mahara Mahara 15.04.3
Mahara Mahara 15.04.4
Mahara Mahara 15.04.6
Mahara Mahara 15.10.1
Mahara Mahara 15.10.2
Mahara Mahara 15.10.0
9.8
CVSSv3
CVE-2017-1000153
Mahara 15.04 prior to 15.04.10 and 15.10 prior to 15.10.6 and 16.04 prior to 16.04.4 are vulnerable to incorrect access control after the password reset link is sent via email and then user changes default email, Mahara fails to invalidate old link.Consequently the link in email ...
Mahara Mahara 15.04
Mahara Mahara 15.04.5
Mahara Mahara 15.04.7
Mahara Mahara 15.04.8
Mahara Mahara 15.04.9
Mahara Mahara 15.04.0
Mahara Mahara 15.04.1
Mahara Mahara 15.04.2
Mahara Mahara 15.04.3
Mahara Mahara 15.04.4
Mahara Mahara 15.04.6
Mahara Mahara 16.04
Mahara Mahara 16.04.1
Mahara Mahara 16.04.3
Mahara Mahara 16.04.0
Mahara Mahara 16.04.2
Mahara Mahara 15.10.3
Mahara Mahara 15.10.5
Mahara Mahara 15.10.0
Mahara Mahara 15.10.1
Mahara Mahara 15.10.2
Mahara Mahara 15.10.4
9.8
CVSSv3
CVE-2017-1000154
Mahara 15.04 prior to 15.04.8 and 15.10 prior to 15.10.4 and 16.04 prior to 16.04.2 are vulnerable to some authentication methods, which do not use Mahara's built-in login form, still allowing users to log in even if their institution was expired or suspended.
Mahara Mahara 15.04.1
Mahara Mahara 15.04.3
Mahara Mahara 15.04
Mahara Mahara 15.04.4
Mahara Mahara 15.04.5
Mahara Mahara 15.04.6
Mahara Mahara 15.04.7
Mahara Mahara 15.04.0
Mahara Mahara 15.04.2
Mahara Mahara 16.04
Mahara Mahara 16.04.1
Mahara Mahara 16.04.0
Mahara Mahara 15.10.3
Mahara Mahara 15.10.0
Mahara Mahara 15.10.1
Mahara Mahara 15.10.2
9.8
CVSSv3
CVE-2017-1000171
Mahara Mobile prior to 1.2.1 is vulnerable to passwords being sent to the Mahara access log in plain text.
Mahara Mahara Mobile
9.6
CVSSv3
CVE-2011-3642
Cross-site scripting (XSS) vulnerability in Flowplayer Flash 3.2.7 up to and including 3.2.16, as used in the News system (news) extension for TYPO3 and Mahara, allows remote malicious users to inject arbitrary web script or HTML via the plugin configuration directive in a refere...
Flowplayer Flowplayer Flash
1 EDB exploit
9.1
CVSSv3
CVE-2012-2239
Mahara 1.4.x prior to 1.4.4 and 1.5.x prior to 1.5.3 allows remote malicious users to read arbitrary files or create TCP connections via an XML external entity (XXE) injection attack, as demonstrated by reading config.php.
Mahara Mahara
Debian Debian Linux 6.0
8.8
CVSSv3
CVE-2022-28892
Mahara prior to 20.10.5, 21.04.4, 21.10.2, and 22.04.0 is vulnerable to Cross Site Request Forgery (CSRF) because randomly generated tokens are too easily guessable.
Mahara Mahara 22.04.0
Mahara Mahara
8.8
CVSSv3
CVE-2017-1000148
Mahara 15.04 prior to 15.04.8 and 15.10 prior to 15.10.4 and 16.04 prior to 16.04.2 are vulnerable to PHP code execution as Mahara would pass portions of the XML through the PHP "unserialize()" function when importing a skin from an XML file.
Mahara Mahara 15.04.2
Mahara Mahara 15.04.3
Mahara Mahara 15.04.4
Mahara Mahara 15.04.5
Mahara Mahara 15.04
Mahara Mahara 15.04.1
Mahara Mahara 15.04.6
Mahara Mahara 15.04.0
Mahara Mahara 15.04.7
Mahara Mahara 16.04
Mahara Mahara 16.04.0
Mahara Mahara 16.04.1
Mahara Mahara 15.10.1
Mahara Mahara 15.10.3
Mahara Mahara 15.10.0
Mahara Mahara 15.10.2
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
denial of service
CVE-2024-27371
CVE-2024-20405
CVE-2024-31627
CVE-2024-31625
race condition
CVE-2024-4358
cross-site scripting
CVE-2023-20938
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
5
NEXT »