CVE-2017-1000138: XSS
Published Nov 3, 2017
·Updated
Mahara 1.10 before 1.10.0 and 15.04 before 15.04.0 are vulnerable to possible cross site scripting when dragging/dropping files into a collection if the file has Javascript code in its title.
Affected Software
3 affected components
Mahara Mahara=1.10-rc1
Mahara Mahara=15.04-rc1
Mahara Mahara=15.04-rc2
Remediation
Patch Available
Event History
Nov 3, 2017
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2017-1000138.
2
What is the severity of CVE-2017-1000138?
The severity of CVE-2017-1000138 is medium (5.4).
3
How does CVE-2017-1000138 impact Mahara versions 1.10 and 15.04?
CVE-2017-1000138 allows for possible cross-site scripting when dragging/dropping files into a collection if the file has Javascript code in its title.
4
Which versions of Mahara are affected by CVE-2017-1000138?
Mahara versions 1.10 before 1.10.0 and 15.04 before 15.04.0 are affected by CVE-2017-1000138.
5
How can I fix CVE-2017-1000138?
To fix CVE-2017-1000138, you should update your Mahara installation to version 1.10.0 or 15.04.0 or later.