Forums | Mahara Community

Security Announcements /
Security fixes in HTML Purifier 4.3.0


This topic is closed. Only moderators and the group administrators can post new replies.
François Marier's profile picture
Posts: 411

28 March 2011, 21:08

Category: Insecure bundled library
Severity: High
Versions affected: < 1.2.8, < 1.3.5
Reported by: HTML Purifier Project
Identifier: CVE-2011-????

The copy of HTML Purifier bundled with Mahara is vulnerable to several security vulnerabilities. All supported versions of Mahara now have an updated copy of HTML Purifier.

Upgrading to Mahara 1.2.8 or 1.3.5 is strongly recommended for all sites.

1 result