Vulnerabilities
Vulnerable Software
Mahara:  >> Mahara  >> 21.04.1  Security Vulnerabilities
In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, adjusting the path component for the page help file allows attackers to bypass the intended access control for HTML files via directory traversal. It replaces the - character with the / character.
CVSS Score
3.3
EPSS Score
0.001
Published
2021-11-02
In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, certain tag syntax could be used for XSS, such as via a SCRIPT element.
CVSS Score
5.4
EPSS Score
0.005
Published
2021-11-02
In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, exporting collections via PDF export could lead to code execution via shell metacharacters in a collection name. Additional, in Mahara before 20.10.4, 21.04.3, and 21.10.1, exporting collections via PDF export could cause code execution
CVSS Score
7.3
EPSS Score
0.008
Published
2021-11-02


Contact Us

Shodan ® - All rights reserved