← Back

CVE-2018-6182

nvd nist
Published: Apr 9, 2018Modified: Nov 21, 2024

JSON object

Loading...
6.1
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD

Description

Mahara 16.10 before 16.10.9 and 17.04 before 17.04.7 and 17.10 before 17.10.4 are vulnerable to bad input when TinyMCE is bypassed by POST packages. Therefore, Mahara should not rely on TinyMCE's code stripping alone but also clean input on the server / PHP side as one can create own packets of POST data containing bad content with which to hit the server.

Affected (3)

Products: Mahara: Mahara
1 product
Mahara
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Mahara
From 16.10 to 16.10.9
From 17.04 to 17.04.7
From 17.10 to 17.10.4

References (4)

Source: cve@mitre.org
Issue TrackingThird Party Advisory
Source: cve@mitre.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.