4.3
CVSSv2

CVE-2011-0439

Published: 28/03/2011 Updated: 17/08/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in Mahara 1.2.x prior to 1.2.7 and 1.3.x prior to 1.3.4 allows remote malicious users to inject arbitrary web script or HTML via the Pieforms select box.

Vulnerable Product Search on Vulmon Subscribe to Product

mahara mahara 1.2.0

mahara mahara 1.2.3

mahara mahara 1.2.5

mahara mahara 1.2.1

mahara mahara 1.2.2

mahara mahara 1.2.6

mahara mahara 1.3.3

mahara mahara 1.2.4

mahara mahara 1.3.0

mahara mahara 1.3.2

mahara mahara 1.3.1

Vendor Advisories

Two security vulnerabilities have been discovered in Mahara, a fully featured electronic portfolio, weblog, resume builder and social networking system: CVE-2011-0439 A security review commissioned by a Mahara user discovered that Mahara processes unsanitized input which can lead to cross-site scripting (XSS) CVE-2011-0440 Mahara ...