CVE-2011-2771: XSS
Multiple cross-site scripting (XSS) vulnerabilities in Mahara before 1.4.1 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) URI attributes and (2) the External Feed component, as demonstrated by the guid element in an RSS feed.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2011-2771?
CVE-2011-2771 has a medium severity rating due to its potential for cross-site scripting attacks.
How do I fix CVE-2011-2771?
To fix CVE-2011-2771, upgrade Mahara to version 1.4.1 or later, where the vulnerabilities have been addressed.
What versions of Mahara are affected by CVE-2011-2771?
CVE-2011-2771 affects Mahara versions prior to 1.4.1, including versions like 1.3.7 and earlier.
What type of vulnerability is CVE-2011-2771?
CVE-2011-2771 is classified as a cross-site scripting (XSS) vulnerability.
Can CVE-2011-2771 lead to data theft?
Yes, CVE-2011-2771 can lead to data theft as attackers could inject malicious scripts into trusted web pages.