Forums | Mahara Community
Security Announcements
/
SQL injection in 1.1.8 and 1.2.4
02 July 2010, 0:05
Category: | SQL injection |
Severity: | Medium |
Versions affected: | < 1.1.9, < 1.2.5 |
Reported by: | Mahara Team |
Identifier: | CVE-2010-1669 |
As part of a major security review, the Mahara team has identified a SQL injection bug in the 1.1 and 1.2 series of Mahara (the 1.0 series is not affected).
Upgrading to Mahara 1.1.9 or 1.2.5 is recommended for all sites.