PT-2020-14704 · Catalyst It · Mahara
Adesh Nandkishor Kolte
·
Published
2020-08-07
·
Updated
2020-08-12
·
CVE-2020-15907
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Mahara versions 19.04 through 19.04.5
Mahara versions 19.10 through 19.10.3
Mahara versions 20.04 through 20.04.0
Description
The issue allows certain places to execute file or folder names containing JavaScript, potentially leading to security risks.
Recommendations
For Mahara versions 19.04 through 19.04.5, update to version 19.04.6 or later.
For Mahara versions 19.10 through 19.10.3, update to version 19.10.4 or later.
For Mahara versions 20.04 through 20.04.0, update to version 20.04.1 or later.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mahara