LWN.net Logo

mahara: multiple vulnerabilities

Package(s):mahara CVE #(s):CVE-2011-2771 CVE-2011-2772 CVE-2011-2773
Created:November 7, 2011 Updated:November 9, 2011
Description:

From the Debian advisory:

CVE-2011-2771: Teemu Vesala discovered that missing input sanitising of RSS feeds could lead to cross-site scripting.

CVE-2011-2772: Richard Mansfield discovered that insufficient upload restrictions allowed denial of service.

CVE-2011-2773: Richard Mansfield that the management of institutions was prone to cross-site request forgery.

(no CVE ID available yet): Andrew Nichols discovered a privilege escalation vulnerability in MNet handling.

Alerts:
Debian DSA-2334-1 2011-11-04

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds