PT-2019-6758 · Catalyst It · Mahara

Emanuel Bronshtein

·

Publicado

2019-11-13

·

Atualizado

2019-12-21

·

CVE-2012-2237

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Mahara versions 1.4.x through 1.4.2 Mahara versions 1.5.x through 1.5.1
Description Multiple cross-site scripting (XSS) vulnerabilities allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) javascript innerHTML as used when generating login forms, (2) links or (3) resources URLs, and (4) the Display name in a user profile.
Recommendations For Mahara versions 1.4.x through 1.4.2, update to version 1.4.3 or later. For Mahara versions 1.5.x through 1.5.1, update to version 1.5.2 or later.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2012-2237
DSA-2540-1

Produtos afetados

Mahara