CVE-2017-1000144: XSS
Mahara 1.9 before 1.9.6 and 1.10 before 1.10.4 and 15.04 before 15.04.1 are vulnerable to a site admin or institution admin being able to place HTML and Javascript into an institution display name, which will be displayed to other users unescaped on some Mahara system pages.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-1000144?
The severity of CVE-2017-1000144 is medium.
How does CVE-2017-1000144 affect Mahara?
CVE-2017-1000144 allows a site admin or institution admin to place HTML and Javascript into an institution display name, which will be displayed to other users unescaped on some Mahara system pages.
Which versions of Mahara are affected by CVE-2017-1000144?
Mahara 1.9 before 1.9.6, 1.10 before 1.10.4, and 15.04 before 15.04.1 are affected by CVE-2017-1000144.
How can I fix CVE-2017-1000144?
To fix CVE-2017-1000144, upgrade Mahara to version 1.9.6, 1.10.4, or 15.04.1.
Where can I find more information about CVE-2017-1000144?
You can find more information about CVE-2017-1000144 at the following link: [https://bugs.launchpad.net/mahara/+bug/1447377](https://bugs.launchpad.net/mahara/+bug/1447377)