4.3
CVSSv2

CVE-2009-0664

Published: 23/04/2009 Updated: 29/04/2009
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in Mahara 1.0.x prior to 1.0.11 and 1.1.x prior to 1.1.3 allow remote malicious users to inject arbitrary web script or HTML via (1) the introduction field in a user profile or (2) an arbitrary text block in a user view.

Vulnerable Product Search on Vulmon Subscribe to Product

mahara mahara 1.0.5

mahara mahara 1.0.8

mahara mahara 1.0.1

mahara mahara 1.1.0

mahara mahara 1.1.1

mahara mahara 1.0.0

mahara mahara 1.0.4

mahara mahara 1.0.7

mahara mahara 1.0.2

mahara mahara 1.1.2

mahara mahara 1.0.9

mahara mahara 1.0.6

mahara mahara 1.0.3

mahara mahara 1.0.10

Vendor Advisories

It was discovered that mahara, an electronic portfolio, weblog, and resume builder, is prone to cross-site scripting (XSS) attacks because of missing input sanitization of the introduction text field in user profiles and any text field in a user view The oldstable distribution (etch) does not contain mahara For the stable distribution (lenny), th ...