Forums | Mahara Community
Security Announcements
/
Security fixes in HTML Purifier 4.3.0
28 March 2011, 21:08
Category: | Insecure bundled library |
Severity: | High |
Versions affected: | < 1.2.8, < 1.3.5 |
Reported by: | HTML Purifier Project |
Identifier: | CVE-2011-???? |
The copy of HTML Purifier bundled with Mahara is vulnerable to several security vulnerabilities. All supported versions of Mahara now have an updated copy of HTML Purifier.
Upgrading to Mahara 1.2.8 or 1.3.5 is strongly recommended for all sites.