CVE-2017-1000147
Severity CVSS v4.0:
Pending analysis
Type:
CWE-352
Cross-Site Request Forgery (CSRF)
Publication date:
03/11/2017
Last modified:
20/04/2025
Description
Mahara 1.9 before 1.9.8 and 1.10 before 1.10.6 and 15.04 before 15.04.3 are vulnerable to perform a cross-site request forgery (CSRF) attack on the uploader contained in Mahara's filebrowser widget. This could allow an attacker to trick a Mahara user into unknowingly uploading malicious files into their Mahara account.
Impact
Base Score 3.x
6.80
Severity 3.x
MEDIUM
Base Score 2.0
6.00
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:mahara:mahara:1.9:rc1:*:*:*:*:*:* | ||
cpe:2.3:a:mahara:mahara:1.9.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:mahara:mahara:1.9.1:*:*:*:*:*:*:* | ||
cpe:2.3:a:mahara:mahara:1.9.2:*:*:*:*:*:*:* | ||
cpe:2.3:a:mahara:mahara:1.9.3:*:*:*:*:*:*:* | ||
cpe:2.3:a:mahara:mahara:1.9.4:*:*:*:*:*:*:* | ||
cpe:2.3:a:mahara:mahara:1.9.5:*:*:*:*:*:*:* | ||
cpe:2.3:a:mahara:mahara:1.9.6:*:*:*:*:*:*:* | ||
cpe:2.3:a:mahara:mahara:1.9.7:*:*:*:*:*:*:* | ||
cpe:2.3:a:mahara:mahara:1.10:rc1:*:*:*:*:*:* | ||
cpe:2.3:a:mahara:mahara:1.10.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:mahara:mahara:1.10.1:*:*:*:*:*:*:* | ||
cpe:2.3:a:mahara:mahara:1.10.2:*:*:*:*:*:*:* | ||
cpe:2.3:a:mahara:mahara:1.10.3:*:*:*:*:*:*:* | ||
cpe:2.3:a:mahara:mahara:1.10.4:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page