Back to search
CVE-2017-9551
Published: Sep 25, 2017
Modified: Aug 5, 2024
PUBLISHED
Description
Mahara 15.04 before 15.04.14 and 16.04 before 16.04.8 and 16.10 before 16.10.5 and 17.04 before 17.04.3 are vulnerable to a user submitting potential dangerous payload, e.g. XSS code, to be saved as their name in the usr_registration table. The values are then emailed to the the user and administrator and if accepted become part of the new user's account.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
https://mahara.org/interaction/forum/topic.php?id=8040
x_refsource_CONFIRM
https://bugs.launchpad.net/mahara/+bug/1697308
x_refsource_CONFIRM
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now