Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2012-6037

Multiple cross-site scripting (XSS) vulnerabilities in Mahara 1.4.x before 1.4.5 and 1.5.x before 1.5.4, and other versions including 1.2, allow remote attackers to inject arbitrary web script or HTML via a CSV header with "unknown fields," which are not properly handled in error messages in the (1) bulk user, (2) group, and (3) group member upload capabilities. NOTE: this issue was originally part of CVE-2012-2243, but that ID was SPLIT due to different issues by different researchers.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 52.6%
CVSS Severity
CVSS v2 Score 4.3
Products affected by CVE-2012-6037
  • Mahara » Mahara » Version: 1.4
    cpe:2.3:a:mahara:mahara:1.4
  • Mahara » Mahara » Version: 1.4.0
    cpe:2.3:a:mahara:mahara:1.4.0
  • Mahara » Mahara » Version: 1.4.1
    cpe:2.3:a:mahara:mahara:1.4.1
  • Mahara » Mahara » Version: 1.4.2
    cpe:2.3:a:mahara:mahara:1.4.2
  • Mahara » Mahara » Version: 1.4.3
    cpe:2.3:a:mahara:mahara:1.4.3
  • Mahara » Mahara » Version: 1.4.4
    cpe:2.3:a:mahara:mahara:1.4.4
  • Mahara » Mahara » Version: 1.5
    cpe:2.3:a:mahara:mahara:1.5
  • Mahara » Mahara » Version: 1.5.0
    cpe:2.3:a:mahara:mahara:1.5.0
  • Mahara » Mahara » Version: 1.5.1
    cpe:2.3:a:mahara:mahara:1.5.1
  • Mahara » Mahara » Version: 1.5.2
    cpe:2.3:a:mahara:mahara:1.5.2
  • Mahara » Mahara » Version: 1.5.3
    cpe:2.3:a:mahara:mahara:1.5.3


Contact Us

Shodan ® - All rights reserved