4.3
CVSSv2

CVE-2012-2237

Published: 17/12/2019 Updated: 21/12/2019
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in Mahara 1.4.x prior to 1.4.3 and 1.5.x prior to 1.5.2 allow remote malicious users to inject arbitrary web script or HTML via vectors related to (1) javascript innerHTML as used when generating login forms, (2) links or (3) resources URLs, and (4) the Display name in a user profile.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mahara mahara

debian debian linux 6.0

Exploits

source: wwwsecurityfocuscom/bid/54776/info Mahara is prone to multiple cross-site scripting vulnerabilities and an HTML-injection vulnerability because it fails to properly sanitize user-supplied text Successful exploits will allow attacker-supplied HTML and script code to run in the context of the affected browser, potentially allowing ...