4.3
CVSSv2

CVE-2011-2771

Published: 15/11/2011 Updated: 15/11/2011
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in Mahara prior to 1.4.1 allow remote malicious users to inject arbitrary web script or HTML via vectors related to (1) URI attributes and (2) the External Feed component, as demonstrated by the guid element in an RSS feed.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mahara mahara 1.0.9

mahara mahara 1.1.2

mahara mahara 1.3.5

mahara mahara 1.0.6

mahara mahara 1.1.1

mahara mahara 0.9.2

mahara mahara 1.0.12

mahara mahara 1.3.0

mahara mahara 1.0.10

mahara mahara 1.0.13

mahara mahara 1.1.6

mahara mahara 1.2.0

mahara mahara 1.3.4

mahara mahara 1.0.5

mahara mahara 1.1.0

mahara mahara 1.0.4

mahara mahara 0.9.1

mahara mahara 1.2.6

mahara mahara 1.1.5

mahara mahara 1.1.9

mahara mahara 1.0.15

mahara mahara 1.1

mahara mahara 1.2.2

mahara mahara 1.2.5

mahara mahara 1.3.7

mahara mahara 1.0.7

mahara mahara 1.0.2

mahara mahara 1.0.0

mahara mahara 1.1.3

mahara mahara 1.2.4

mahara mahara 1.2.3

mahara mahara 1.2.1

mahara mahara 0.9.0

mahara mahara 1.4

mahara mahara

mahara mahara 1.0.8

mahara mahara 1.0.3

mahara mahara 1.0.1

mahara mahara 1.3.1

mahara mahara 1.3.2

mahara mahara 1.0.11

mahara mahara 1.1.4

mahara mahara 1.0.14

mahara mahara 1.1.7

mahara mahara 1.1.8

mahara mahara 1.3.3

mahara mahara 1.3.6

Vendor Advisories

Several vulnerabilities were discovered in Mahara, an electronic portfolio, weblog, and resume builder: CVE-2011-2771 Teemu Vesala discovered that missing input sanitising of RSS feeds could lead to cross-site scripting CVE-2011-2772 Richard Mansfield discovered that insufficient upload restrictions allowed denial of service CVE-2011 ...