First published: Tue Nov 15 2011(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in Mahara before 1.4.1 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) URI attributes and (2) the External Feed component, as demonstrated by the guid element in an RSS feed.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mahara Mahara | =1.1.0-beta4 | |
Mahara Mahara | =1.1.6 | |
Mahara Mahara | =1.2.0 | |
Mahara Mahara | =0.9.1 | |
Mahara Mahara | =1.1.2 | |
Mahara Mahara | =1.2.3 | |
Mahara Mahara | =1.0.4 | |
Mahara Mahara | =1.1.7 | |
Mahara Mahara | =1.2.1 | |
Mahara Mahara | =1.3.2 | |
Mahara Mahara | =0.9.2 | |
Mahara Mahara | =1.4-rc2 | |
Mahara Mahara | =1.0.1 | |
Mahara Mahara | =1.0.8 | |
Mahara Mahara | =1.2.0-rc1 | |
Mahara Mahara | =1.2.0-alpha1 | |
Mahara Mahara | =1.0.12 | |
Mahara Mahara | =1.0.15 | |
Mahara Mahara | =1.0.6 | |
Mahara Mahara | =1.3.0-beta1 | |
Mahara Mahara | =1.0.9 | |
Mahara Mahara | =1.2.0-alpha2 | |
Mahara Mahara | =1.3.0-rc1 | |
Mahara Mahara | =1.1.9 | |
Mahara Mahara | =1.0.5 | |
Mahara Mahara | =1.1 | |
Mahara Mahara | =1.2.0-beta4 | |
Mahara Mahara | =1.3.7 | |
Mahara Mahara | =1.4-rc4 | |
Mahara Mahara | =1.1.0-alpha3 | |
Mahara Mahara | =1.1.4 | |
Mahara Mahara | =1.2.0-alpha3 | |
Mahara Mahara | =1.2.0-beta2 | |
Mahara Mahara | =1.2.6 | |
Mahara Mahara | =1.3.0 | |
Mahara Mahara | =1.0.2 | |
Mahara Mahara | =1.1.0-beta1 | |
Mahara Mahara | =1.0.3 | |
Mahara Mahara | =1.4-rc3 | |
Mahara Mahara | =1.3.6 | |
Mahara Mahara | =1.0.13 | |
Mahara Mahara | =1.3.1 | |
Mahara Mahara | =1.0.10 | |
Mahara Mahara | =1.1.0-rc2 | |
Mahara Mahara | =1.1.1 | |
Mahara Mahara | =1.3.0-beta2 | |
Mahara Mahara | =1.1.8 | |
Mahara Mahara | =1.1.0-beta3 | |
Mahara Mahara | =1.2.4 | |
Mahara Mahara | =1.1.0-alpha1 | |
Mahara Mahara | =1.3.5 | |
Mahara Mahara | =1.3.0-beta3 | |
Mahara Mahara | <=1.4.0 | |
Mahara Mahara | =1.1.0-alpha2 | |
Mahara Mahara | =1.4-rc1 | |
Mahara Mahara | =1.2.2 | |
Mahara Mahara | =1.2.5 | |
Mahara Mahara | =1.1.3 | |
Mahara Mahara | =1.3.4 | |
Mahara Mahara | =1.0.7 | |
Mahara Mahara | =1.0.0 | |
Mahara Mahara | =1.1.0 | |
Mahara Mahara | =1.1.5 | |
Mahara Mahara | =1.2.0-beta1 | |
Mahara Mahara | =1.1.0-beta2 | |
Mahara Mahara | =1.1.0-rc1 | |
Mahara Mahara | =1.2.0-beta3 | |
Mahara Mahara | =1.3.3 | |
Mahara Mahara | =1.0.14 | |
Mahara Mahara | =1.3.0-beta4 | |
Mahara Mahara | =1.0.11 | |
Mahara Mahara | =0.9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-2771 has a medium severity rating due to its potential for cross-site scripting attacks.
To fix CVE-2011-2771, upgrade Mahara to version 1.4.1 or later, where the vulnerabilities have been addressed.
CVE-2011-2771 affects Mahara versions prior to 1.4.1, including versions like 1.3.7 and earlier.
CVE-2011-2771 is classified as a cross-site scripting (XSS) vulnerability.
Yes, CVE-2011-2771 can lead to data theft as attackers could inject malicious scripts into trusted web pages.