LWN.net Logo

mahara: insufficient input sanitization

Package(s):mahara CVE #(s):
Created:June 23, 2009 Updated:June 24, 2009
Description: From the Debian advisory: It was discovered that mahara, an electronic portfolio, weblog, and resume builder is prone to several cross-site scripting attacks, which allow an attacker to inject arbitrary HTML or script code and steal potential sensitive data from other users.
Alerts:
Debian DSA-1822-1 2009-06-23

(Log in to post comments)

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds