Page 13 of 99 results (0.004 seconds)

CVSS: 5.5EPSS: 0%CPEs: 24EXPL: 0

Mahara before 1.5.12, 1.6.x before 1.6.7, and 1.7.x before 1.7.3 does not properly prevent access to blocks, which allows remote authenticated users to modify arbitrary blocks via the bock id in an edit request. Mahara anterior a 1.5.12, 1.6.x anterior a 1.6.7 y 1.7.x anterior a 1.7.3 no previene debidamente acceso a bloques, lo que permite a usuarios remotos autenticados modificar bloques arbitrarios a través del bock id en una solicitud de editar. • http://www.openwall.com/lists/oss-security/2013/10/08/3 http://www.openwall.com/lists/oss-security/2013/10/15/1 http://www.openwall.com/lists/oss-security/2013/10/16/7 https://bugs.launchpad.net/mahara/+bug/1233500 https://mahara.org/interaction/forum/topic.php?id=5753 • CWE-264: Permissions, Privileges, and Access Controls •

CVSS: 4.0EPSS: 0%CPEs: 24EXPL: 0

Mahara before 1.5.12, 1.6.x before 1.6.7, and 1.7.x before 1.7.3 does not properly restrict access to artefacts, which allows remote authenticated users to read arbitrary artefacts via the (1) artefact id in an upload action when creating a journal or (2) instconf_artefactid_selected[ID] parameter in an upload action when editing a block. Mahara anterior a 1.5.12, 1.6.x anterior a 1.6.7 y 1.7.x anterior a 1.7.3 no restringe debidamente acceso a artefactos, lo que permite a usuarios remotos autenticados leer artefactos arbitrarios a través del (1) id del artefacto en una acción de subida cuando crea un diario o (2) parámetro instconf_artefactid_selected[ID] en una acción de subida cuando edita un bloque. • http://www.openwall.com/lists/oss-security/2013/10/08/3 http://www.openwall.com/lists/oss-security/2013/10/15/1 http://www.openwall.com/lists/oss-security/2013/10/16/7 https://bugs.launchpad.net/mahara/+bug/1211758 https://mahara.org/interaction/forum/topic.php?id=5753 • CWE-264: Permissions, Privileges, and Access Controls •

CVSS: 4.0EPSS: 0%CPEs: 27EXPL: 0

Mahara before 1.5.13, 1.6.x before 1.6.8, and 1.7.x before 1.7.4 does not properly restrict access to folders, which allows remote authenticated users to read arbitrary folders (1) by leveraging an active folder tab loaded before permissions were removed or (2) via the folder parameter to artefact/file/groupfiles.php. Mahara anterior a 1.5.13, 1.6.x anterior a 1.6.8 y 1.7.x anterior a 1.7.4 no restringe debidamente acceso a carpetas, lo que permite a usuarios remotos autenticados leer carpetas arbitrarias (1) mediante el aprovechamiento de una etiqueta de carpeta activa cargada antes de que los permisos fueron eliminados o (2) a través del parámetro folder hacia artefact/file/groupfiles.php. • http://www.openwall.com/lists/oss-security/2013/10/08/3 http://www.openwall.com/lists/oss-security/2013/10/15/1 http://www.openwall.com/lists/oss-security/2013/10/16/7 https://bugs.launchpad.net/mahara/+bug/1034180 https://mahara.org/interaction/forum/topic.php?id=5864 • CWE-264: Permissions, Privileges, and Access Controls •

CVSS: 6.0EPSS: 0%CPEs: 14EXPL: 0

Mahara 1.4.x before 1.4.5 and 1.5.x before 1.5.4 allows remote authenticated administrators to execute arbitrary programs by modifying the path to clamav. NOTE: this can be exploited without authentication by leveraging CVE-2012-2243. Mahara v1.4.x anterior a v1.4.5 y v1.5.x anterior a v1.5.4 permite a los administradores remotos autenticados ejecutar programas arbitrarios mediante la modificación de la ruta de acceso a clamav. NOTA: puede ser explotada sin autenticación mediante el aprovechamiento de CVE-2012-2243. • http://www.debian.org/security/2012/dsa-2591 https://bugs.launchpad.net/mahara/+bug/1057238 https://mahara.org/interaction/forum/topic.php?id=4936 • CWE-264: Permissions, Privileges, and Access Controls •

CVSS: 4.3EPSS: 0%CPEs: 15EXPL: 0

Cross-site scripting (XSS) vulnerability in Mahara 1.4.x before 1.4.5 and 1.5.x before 1.5.4 allows remote attackers to inject arbitrary web script or HTML via vectors related to artefact/file/ and a crafted SVG file. Vulnerabilidad de ejecución de secuencias de comandos en sitios cruzados (XSS) en group/members.php in Mahara v1.4.x anterior a v1.4.5 y v1.5.x anterior a v1.5.4 permite a atacantes remotos inyectar secuencias de comandos web o HTML a través vectores relacionados con artefact/file/ y un fichero SVG manipulado. • http://www.debian.org/security/2012/dsa-2591 https://bugs.launchpad.net/mahara/+bug/1061980 https://mahara.org/interaction/forum/topic.php?id=4938 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •