First published: Mon Feb 09 2009(Updated: )
Cross-site scripting (XSS) vulnerability in Mahara before 1.0.9 allows remote attackers to inject arbitrary web script or HTML via a crafted forum post.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mahara | =0.9.1 | |
Mahara | <=1.0.8 | |
Mahara | =1.0.4 | |
Mahara | =0.9.2 | |
Mahara | =1.0.1 | |
Mahara | =1.0.6 | |
Mahara | =1.0.5 | |
Mahara | =1.0.2 | |
Mahara | =1.0.3 | |
Mahara | =1.0.7 | |
Mahara | =1.0.0 | |
Mahara | =0.9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-0487 is classified as a medium severity vulnerability due to the potential for cross-site scripting attacks.
Fixing CVE-2009-0487 involves upgrading Mahara to version 1.0.9 or later to mitigate the XSS vulnerability.
The potential impacts of CVE-2009-0487 include unauthorized user actions, data theft, or phishing attacks through injected scripts.
CVE-2009-0487 affects Mahara versions prior to 1.0.9, including 0.9.1 to 1.0.8.
CVE-2009-0487 is a documented cross-site scripting vulnerability and is recognized in various cybersecurity resources, indicating its commonality.