CVE-2019-9709
Dashboard / Vulnerabilities / CVE-2019-9709
CVE-2019-9709
Published: 7 May 2019Last Modified: 8 Jul 2026
Summary:
Details: An issue was discovered in Mahara 17.10 before 17.10.8, 18.04 before 18.04.4, and 18.10 before 18.10.1. The collection title is vulnerable to Cross Site Scripting (XSS) due to not escaping it when viewing the collection's SmartEvidence overview page (if that feature is turned on). This can be exploited by any logged-in user.
References: https://mahara.org/interaction/forum/topic.php?id=8446, https://bugs.launchpad.net/bugs/1819547
Affected packages
Package
Name:
Purl:
Affected ranges
Type: GIT
Events:
Introduced- 7e3e132425fc023eb85e66717284540d80bdacd1
Affected versions
17.10.7_RELEASE
17.10.6_RELEASE
17.10.5_RELEASE
17.10.4_RELEASE
17.10.3_RELEASE
17.10.2_RELEASE
17.10.1_RELEASE
17.10.0_RELEASE
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
