6.5
CVSSv2

CVE-2017-1000148

Published: 03/11/2017 Updated: 03/10/2019
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 578
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

Mahara 15.04 prior to 15.04.8 and 15.10 prior to 15.10.4 and 16.04 prior to 16.04.2 are vulnerable to PHP code execution as Mahara would pass portions of the XML through the PHP "unserialize()" function when importing a skin from an XML file.

Vulnerable Product Search on Vulmon Subscribe to Product

mahara mahara 15.04.2

mahara mahara 15.04.3

mahara mahara 15.04.4

mahara mahara 15.04.5

mahara mahara 15.04

mahara mahara 15.04.1

mahara mahara 15.04.6

mahara mahara 15.04.0

mahara mahara 15.04.7

mahara mahara 16.04

mahara mahara 16.04.0

mahara mahara 16.04.1

mahara mahara 15.10.1

mahara mahara 15.10.3

mahara mahara 15.10.0

mahara mahara 15.10.2