Security issue relating to cross-site scripting <16.10.7; <17.04.5; <17.10.2

17 January 2018, 17:09

Fix user input from direct POST / GET usage

Vuln type: CSS
Impact: Code execution

Mahara 16.10 before 16.10.7, 17.04 before 17.04.5 and 17.10 before 17.10.2 are vulnerable to a user submitting a potential dangerous payload, e.g., XSS code, to be passed in as POST or GET data.

Reported by: Yuliya Bozhko
Bug report:
CVE number: CVE-2017-17454

