CVE-2012-2247

Cross-site scripting (XSS) vulnerability in Mahara 1.4.x before 1.4.5 and 1.5.x before 1.5.4 allows remote attackers to inject arbitrary web script or HTML via vectors related to artefact/file/ and a crafted SVG file.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mahara:mahara:1.4:rc1:*:*:*:*:*:*
cpe:2.3:a:mahara:mahara:1.4:rc2:*:*:*:*:*:*
cpe:2.3:a:mahara:mahara:1.4.3:*:*:*:*:*:*:*
cpe:2.3:a:mahara:mahara:1.4.4:*:*:*:*:*:*:*
cpe:2.3:a:mahara:mahara:1.4.1:*:*:*:*:*:*:*
cpe:2.3:a:mahara:mahara:1.4.2:*:*:*:*:*:*:*
cpe:2.3:a:mahara:mahara:1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:mahara:mahara:1.4:rc3:*:*:*:*:*:*
cpe:2.3:a:mahara:mahara:1.4:rc4:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:mahara:mahara:1.5.3:*:*:*:*:*:*:*
cpe:2.3:a:mahara:mahara:1.5:rc1:*:*:*:*:*:*
cpe:2.3:a:mahara:mahara:1.5.1:*:*:*:*:*:*:*
cpe:2.3:a:mahara:mahara:1.5.2:*:*:*:*:*:*:*
cpe:2.3:a:mahara:mahara:1.5.0:*:*:*:*:*:*:*
cpe:2.3:a:mahara:mahara:1.5:rc2:*:*:*:*:*:*

Information

Published : 2012-11-24 12:55

Updated : 2013-02-07 20:50


NVD link : CVE-2012-2247

Mitre link : CVE-2012-2247


JSON object : View

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Advertisement

dedicated server usa

Products Affected

mahara

  • mahara