CVE-2017-17454: XSS
Mahara 16.10 before 16.10.7 and 17.04 before 17.04.5 and 17.10 before 17.10.2 have a Cross Site Scripting (XSS) vulnerability when a user enters invalid UTF-8 characters. These are now going to be discarded in Mahara along with NULL characters and invalid Unicode characters. Mahara will also avoid direct $GET and $POST usage where possible, and instead use paramexists() and the correct param() function to fetch the expected value.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this Mahara issue?
The vulnerability ID for this Mahara issue is CVE-2017-17454.
What is the severity of CVE-2017-17454?
The severity of CVE-2017-17454 is medium with a CVSS score of 5.4.
How does CVE-2017-17454 affect Mahara?
CVE-2017-17454 affects Mahara versions 16.10 before 16.10.7, 17.04 before 17.04.5, and 17.10 before 17.10.2.
What is the impact of CVE-2017-17454?
CVE-2017-17454 allows an attacker to perform Cross-Site Scripting (XSS) attacks by entering invalid UTF-8 characters.
How can I fix CVE-2017-17454?
To fix CVE-2017-17454, update your Mahara installation to version 16.10.7, 17.04.5, or 17.10.2.