CVE-2020-15907: XSS
In Mahara 19.04 before 19.04.6, 19.10 before 19.10.4, and 20.04 before 20.04.1, certain places could execute file or folder names containing JavaScript.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2020-15907?
CVE-2020-15907 is a vulnerability in Mahara CMS versions 19.04 before 19.04.6, 19.10 before 19.10.4, and 20.04 before 20.04.1 that allows execution of code contained in file or folder names.
How does CVE-2020-15907 affect Mahara?
CVE-2020-15907 affects Mahara CMS versions 19.04 before 19.04.6, 19.10 before 19.10.4, and 20.04 before 20.04.1 by allowing the execution of code contained in certain file or folder names that may contain JavaScript.
What is the severity of CVE-2020-15907?
CVE-2020-15907 has a severity value of 6.1, which is considered medium.
How can I fix CVE-2020-15907?
To fix CVE-2020-15907, it is recommended to upgrade to Mahara CMS versions 19.04.6, 19.10.4, or 20.04.1.
Where can I find more information about CVE-2020-15907?
More information about CVE-2020-15907 can be found at the following references: [1], [2].