CVE-2017-1000140: XSS
Mahara 1.8 before 1.8.7 and 1.9 before 1.9.5 and 1.10 before 1.10.3 and 15.04 before 15.04.0 are vulnerable to a maliciously created .xml file that can have its code executed when user tries to download the file.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-1000140?
The severity of CVE-2017-1000140 is medium with a CVSS score of 5.4.
How does CVE-2017-1000140 affect Mahara?
CVE-2017-1000140 affects Mahara versions 1.8 to 1.8.7, 1.9 to 1.9.5, 1.10 to 1.10.3, and 15.04 to 15.04.0.
What is the vulnerability description of CVE-2017-1000140?
CVE-2017-1000140 is a vulnerability in Mahara that allows the execution of malicious code when a user tries to download a .xml file.
How can I fix CVE-2017-1000140?
To fix CVE-2017-1000140, it is recommended to upgrade Mahara to version 1.8.7, 1.9.5, 1.10.3, or 15.04.0 depending on the affected version.
Where can I find more information about CVE-2017-1000140?
You can find more information about CVE-2017-1000140 at the following link: https://bugs.launchpad.net/mahara/+bug/1404117