5.8
CVSSv2

CVE-2011-0440

Published: 28/03/2011 Updated: 17/08/2017
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
VMScore: 516
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:P

Vulnerability Summary

Cross-site request forgery (CSRF) vulnerability in Mahara 1.2.x prior to 1.2.7 and 1.3.x prior to 1.3.4 allows remote malicious users to hijack the authentication of arbitrary users for requests that delete blogs.

Vulnerable Product Search on Vulmon Subscribe to Product

mahara mahara 1.2.0

mahara mahara 1.2.4

mahara mahara 1.2.3

mahara mahara 1.2.1

mahara mahara 1.2.2

mahara mahara 1.2.5

mahara mahara 1.2.6

mahara mahara 1.3.0

mahara mahara 1.3.2

mahara mahara 1.3.3

mahara mahara 1.3.1

Vendor Advisories

Two security vulnerabilities have been discovered in Mahara, a fully featured electronic portfolio, weblog, resume builder and social networking system: CVE-2011-0439 A security review commissioned by a Mahara user discovered that Mahara processes unsanitized input which can lead to cross-site scripting (XSS) CVE-2011-0440 Mahara ...