CVE-2012-2247: XSS
Published Nov 24, 2012
·Updated
Cross-site scripting (XSS) vulnerability in Mahara 1.4.x before 1.4.5 and 1.5.x before 1.5.4 allows remote attackers to inject arbitrary web script or HTML via vectors related to artefact/file/ and a crafted SVG file.
Affected Software
15 affected components
Mahara Mahara=1.4-rc1
Mahara Mahara=1.4-rc2
Mahara Mahara=1.4-rc3
Mahara Mahara=1.4-rc4
Mahara Mahara=1.4.0
Mahara Mahara=1.4.1
Mahara Mahara=1.4.2
Mahara Mahara=1.4.3
Mahara Mahara=1.4.4
Mahara Mahara=1.5-rc1
Mahara Mahara=1.5-rc2
Mahara Mahara=1.5.0
Mahara Mahara=1.5.1
Mahara Mahara=1.5.2
Mahara Mahara=1.5.3
Remediation
Patch Available
Event History
Nov 24, 2012
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-2247?
CVE-2012-2247 is classified as a medium severity vulnerability due to its cross-site scripting (XSS) nature.
2
How do I fix CVE-2012-2247?
To mitigate CVE-2012-2247, upgrade Mahara to version 1.4.5 or 1.5.4 or later.
3
Which versions of Mahara are affected by CVE-2012-2247?
CVE-2012-2247 affects Mahara versions 1.4.x before 1.4.5 and 1.5.x before 1.5.4.
4
What kind of attacks are possible with CVE-2012-2247?
CVE-2012-2247 allows remote attackers to inject arbitrary web scripts or HTML into the application.
5
Is there a specific file type involved in CVE-2012-2247?
Yes, the vulnerability is related to crafted SVG files that can exploit the XSS issue.