MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in Mahara 1.4.x before 1.4.5 and 1.5.x before 1.5.4, and other versions including 1.2, allow remote attackers to inject arbitrary web script or HTML via a CSV header with "unknown fields," which are not properly handled in error messages in the (1) bulk user, (2) group, and (3) group member upload capabilities
Published Nov 24, 2012
4.3
MEDIUMCVSS 2.0
EPSS 1.83%
Description
Affected products
Remediation
Metrics
References (3)
Change history (0)
No recorded changes yet.