First published: Fri Nov 03 2017(Updated: )
Mahara 1.8 before 1.8.7 and 1.9 before 1.9.5 and 1.10 before 1.10.3 and 15.04 before 15.04.0 are vulnerable to a maliciously created .xml file that can have its code executed when user tries to download the file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mahara Mahara | =1.8-rc1 | |
Mahara Mahara | =1.8-rc2 | |
Mahara Mahara | =1.8.0 | |
Mahara Mahara | =1.8.1 | |
Mahara Mahara | =1.8.2 | |
Mahara Mahara | =1.8.3 | |
Mahara Mahara | =1.8.4 | |
Mahara Mahara | =1.8.5 | |
Mahara Mahara | =1.8.6 | |
Mahara Mahara | =1.9-rc1 | |
Mahara Mahara | =1.9.0 | |
Mahara Mahara | =1.9.1 | |
Mahara Mahara | =1.9.2 | |
Mahara Mahara | =1.9.3 | |
Mahara Mahara | =1.9.4 | |
Mahara Mahara | =1.10-rc1 | |
Mahara Mahara | =1.10.0 | |
Mahara Mahara | =1.10.1 | |
Mahara Mahara | =1.10.2 | |
Mahara Mahara | =15.04-rc1 | |
Mahara Mahara | =15.04-rc2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2017-1000140 is medium with a CVSS score of 5.4.
CVE-2017-1000140 affects Mahara versions 1.8 to 1.8.7, 1.9 to 1.9.5, 1.10 to 1.10.3, and 15.04 to 15.04.0.
CVE-2017-1000140 is a vulnerability in Mahara that allows the execution of malicious code when a user tries to download a .xml file.
To fix CVE-2017-1000140, it is recommended to upgrade Mahara to version 1.8.7, 1.9.5, 1.10.3, or 15.04.0 depending on the affected version.
You can find more information about CVE-2017-1000140 at the following link: https://bugs.launchpad.net/mahara/+bug/1404117