CVE-2019-9709

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
07/05/2019
Last modified:
07/05/2019

Description

An issue was discovered in Mahara 17.10 before 17.10.8, 18.04 before 18.04.4, and 18.10 before 18.10.1. The collection title is vulnerable to Cross Site Scripting (XSS) due to not escaping it when viewing the collection's SmartEvidence overview page (if that feature is turned on). This can be exploited by any logged-in user.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mahara:mahara:*:*:*:*:*:*:*:* 17.10.0 (including) 17.10.8 (excluding)
cpe:2.3:a:mahara:mahara:*:*:*:*:*:*:*:* 18.04.0 (including) 18.04.4 (excluding)
cpe:2.3:a:mahara:mahara:*:*:*:*:*:*:*:* 18.10.0 (including) 18.10.1 (excluding)