Forums | Mahara Community
Security announcements
/
Multiple XSS vulnerabilities in Mahara 1.0.9 and 1.1.1
10 March 2009, 3:34
| Category: | Cross-site scripting |
| Severity: | Major |
| Versions affected: | < 1.0.10, < 1.1.2 |
| Reported by: | Mahara Team |
| Identifier: | CVE-2009-0660 |
Multiple cross-site scripting vulnerabilities have been found in user-supplied profile data and blogs.
Upgrading to Mahara 1.0.10 or 1.1.2 is strongly recommended for all sites.
Edits to this post:
-
François Marier
-
10 March 2009, 4:32