CVE-2017-1000148: High severity mahara vulnerability
Published Nov 3, 2017
·Updated
Mahara 15.04 before 15.04.8 and 15.10 before 15.10.4 and 16.04 before 16.04.2 are vulnerable to PHP code execution as Mahara would pass portions of the XML through the PHP "unserialize()" function when importing a skin from an XML file.
Affected Software
18 affected components
Mahara Mahara=15.04-rc1
Mahara Mahara=15.04-rc2
Mahara Mahara=15.04.0
Mahara Mahara=15.04.1
Mahara Mahara=15.04.2
Mahara Mahara=15.04.3
Mahara Mahara=15.04.4
Mahara Mahara=15.04.5
Mahara Mahara=15.04.6
Mahara Mahara=15.04.7
Mahara Mahara=16.04-rc1
Mahara Mahara=16.04-rc2
Mahara Mahara=16.04.0
Mahara Mahara=16.04.1
Mahara Mahara=15.10.0
Mahara Mahara=15.10.1
Mahara Mahara=15.10.2
Mahara Mahara=15.10.3
Remediation
Patch Available
Event History
Nov 3, 2017
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2017-1000148.
2
What is the severity of CVE-2017-1000148?
The severity of CVE-2017-1000148 is high.
3
What software versions are affected by CVE-2017-1000148?
Mahara versions 15.04 before 15.04.8, 15.10 before 15.10.4, and 16.04 before 16.04.2 are affected by CVE-2017-1000148.
4
How does CVE-2017-1000148 exploit the vulnerability?
CVE-2017-1000148 exploits the vulnerability by passing portions of the XML through the PHP "unserialize()" function when importing a skin from an XML file.
5
Is there a fix available for CVE-2017-1000148?
Yes, the fix for CVE-2017-1000148 is to upgrade to Mahara versions 15.04.8, 15.10.4, or 16.04.2.