CVE-2013-1426: XSS
Published Nov 7, 2019
·Updated
Cross-site Scripting (XSS) in Mahara before 1.5.9 and 1.6.x before 1.6.4 allows remote attackers to inject arbitrary web script or HTML via the TinyMCE editor.
Affected Software
3 affected components
debian/mahara
Mahara Mahara<1.5.9
Mahara Mahara>=1.6.0<1.6.4
Remediation
Patch Available
Event History
Nov 7, 2019
CVE Published
via MITRE·08:46 PM
Data Sourced
via MITRE·08:46 PM
DescriptionWeakness
Feb 18, 2026
Data Sourced
via Debian·03:30 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2013-1426.
2
What is the severity of CVE-2013-1426?
The severity of CVE-2013-1426 is medium with a CVSS score of 6.1.
3
What is the description of CVE-2013-1426?
CVE-2013-1426 is a Cross-site Scripting (XSS) vulnerability in Mahara before 1.5.9 and 1.6.x before 1.6.4 that allows remote attackers to inject arbitrary web script or HTML via the TinyMCE editor.
4
Which software is affected by CVE-2013-1426?
Mahara versions before 1.5.9 and 1.6.x before 1.6.4 are affected by CVE-2013-1426.
5
How can I mitigate CVE-2013-1426?
To mitigate CVE-2013-1426, it is recommended to upgrade to Mahara version 1.5.9 or newer, or version 1.6.4 or newer.