First published: Mon Mar 28 2011(Updated: )
Cross-site scripting (XSS) vulnerability in Mahara 1.2.x before 1.2.7 and 1.3.x before 1.3.4 allows remote attackers to inject arbitrary web script or HTML via the Pieforms select box.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mahara Mahara | =1.2.0 | |
Mahara Mahara | =1.2.3 | |
Mahara Mahara | =1.2.1 | |
Mahara Mahara | =1.2.0-rc1 | |
Mahara Mahara | =1.2.0-alpha1 | |
Mahara Mahara | =1.2.0-alpha2 | |
Mahara Mahara | =1.2.0-beta4 | |
Mahara Mahara | =1.2.0-alpha3 | |
Mahara Mahara | =1.2.0-beta2 | |
Mahara Mahara | =1.2.6 | |
Mahara Mahara | =1.2.4 | |
Mahara Mahara | =1.2.2 | |
Mahara Mahara | =1.2.5 | |
Mahara Mahara | =1.2.0-beta1 | |
Mahara Mahara | =1.2.0-beta3 | |
Mahara Mahara | =1.3.3 | |
Mahara Mahara | =1.3.2 | |
Mahara Mahara | =1.3.0-beta1 | |
Mahara Mahara | =1.3.0-rc1 | |
Mahara Mahara | =1.3.0 | |
Mahara Mahara | =1.3.1 | |
Mahara Mahara | =1.3.0-beta2 | |
Mahara Mahara | =1.3.0-beta3 | |
Mahara Mahara | =1.3.0-beta4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-0439 is rated as a medium severity vulnerability due to the potential for cross-site scripting attacks.
To fix CVE-2011-0439, upgrade Mahara to version 1.2.7 or 1.3.4 or later, which addresses the issue.
CVE-2011-0439 affects Mahara versions 1.2.0 through 1.2.6 and 1.3.0 through 1.3.3.
CVE-2011-0439 is a cross-site scripting (XSS) vulnerability that allows attackers to inject arbitrary web scripts or HTML.
No, no authentication is required to exploit CVE-2011-0439, making it accessible to remote attackers.