
CVE-2013-4431
https://notcve.org/view.php?id=CVE-2013-4431
19 May 2014 — Mahara before 1.5.12, 1.6.x before 1.6.7, and 1.7.x before 1.7.3 does not properly prevent access to blocks, which allows remote authenticated users to modify arbitrary blocks via the bock id in an edit request. Mahara anterior a 1.5.12, 1.6.x anterior a 1.6.7 y 1.7.x anterior a 1.7.3 no previene debidamente acceso a bloques, lo que permite a usuarios remotos autenticados modificar bloques arbitrarios a través del bock id en una solicitud de editar. • http://www.openwall.com/lists/oss-security/2013/10/08/3 • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2013-4432
https://notcve.org/view.php?id=CVE-2013-4432
19 May 2014 — Mahara before 1.5.13, 1.6.x before 1.6.8, and 1.7.x before 1.7.4 does not properly restrict access to folders, which allows remote authenticated users to read arbitrary folders (1) by leveraging an active folder tab loaded before permissions were removed or (2) via the folder parameter to artefact/file/groupfiles.php. Mahara anterior a 1.5.13, 1.6.x anterior a 1.6.8 y 1.7.x anterior a 1.7.4 no restringe debidamente acceso a carpetas, lo que permite a usuarios remotos autenticados leer carpetas arbitrarias (... • http://www.openwall.com/lists/oss-security/2013/10/08/3 • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2012-6037
https://notcve.org/view.php?id=CVE-2012-6037
24 Nov 2012 — Multiple cross-site scripting (XSS) vulnerabilities in Mahara 1.4.x before 1.4.5 and 1.5.x before 1.5.4, and other versions including 1.2, allow remote attackers to inject arbitrary web script or HTML via a CSV header with "unknown fields," which are not properly handled in error messages in the (1) bulk user, (2) group, and (3) group member upload capabilities. NOTE: this issue was originally part of CVE-2012-2243, but that ID was SPLIT due to different issues by different researchers. Múltiples vulnerabil... • http://www.debian.org/security/2012/dsa-2591 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2012-2239
https://notcve.org/view.php?id=CVE-2012-2239
24 Nov 2012 — Mahara 1.4.x before 1.4.4 and 1.5.x before 1.5.3 allows remote attackers to read arbitrary files or create TCP connections via an XML external entity (XXE) injection attack, as demonstrated by reading config.php. Mahara v1.4.x anterior a v1.4.4 y v1.5.x anterior a v1.5.3 permite a atacantes remotos leer archivos arbitrarios o crear conexiones TCP a través de un ataque de inyección en una entidad XML externa (XXE), como se demuestra por la lectura de config.php. • http://www.debian.org/security/2012/dsa-2591 • CWE-611: Improper Restriction of XML External Entity Reference •

CVE-2012-2243
https://notcve.org/view.php?id=CVE-2012-2243
24 Nov 2012 — Cross-site scripting (XSS) vulnerability in Mahara 1.4.x before 1.4.5 and 1.5.x before 1.5.4 allows remote attackers to inject arbitrary web script or HTML by uploading an XML file with the xhtml extension, which is rendered inline as script. NOTE: this can be leveraged with CVE-2012-2244 to execute arbitrary code without authentication, as demonstrated by modifying the clamav path. Vulnerabilidad de ejecución de secuencias de comandos en sitios cruzados (XSS) en Mahara v1.4.x anterior a v1.4.5 y v1.5.x ant... • http://www.debian.org/security/2012/dsa-2591 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2012-2244
https://notcve.org/view.php?id=CVE-2012-2244
24 Nov 2012 — Mahara 1.4.x before 1.4.5 and 1.5.x before 1.5.4 allows remote authenticated administrators to execute arbitrary programs by modifying the path to clamav. NOTE: this can be exploited without authentication by leveraging CVE-2012-2243. Mahara v1.4.x anterior a v1.4.5 y v1.5.x anterior a v1.5.4 permite a los administradores remotos autenticados ejecutar programas arbitrarios mediante la modificación de la ruta de acceso a clamav. NOTA: puede ser explotada sin autenticación mediante el aprovechamiento de CVE-2... • http://www.debian.org/security/2012/dsa-2591 • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2012-2246
https://notcve.org/view.php?id=CVE-2012-2246
24 Nov 2012 — Mahara 1.4.x before 1.4.5 and 1.5.x before 1.5.4 allows remote attackers to conduct clickjacking attacks to delete arbitrary users and bypass CSRF protection via account/delete.php. Mahara v1.4.x anterior a v1.4.5 y v1.5.x anterior a v1.5.4 permite a atacantes remotos realizar ataques de clickjacking para eliminar usuarios arbitrarios y eludir la protección CSRF través de account/delete.php • http://www.debian.org/security/2012/dsa-2591 • CWE-20: Improper Input Validation •

CVE-2012-2247
https://notcve.org/view.php?id=CVE-2012-2247
24 Nov 2012 — Cross-site scripting (XSS) vulnerability in Mahara 1.4.x before 1.4.5 and 1.5.x before 1.5.4 allows remote attackers to inject arbitrary web script or HTML via vectors related to artefact/file/ and a crafted SVG file. Vulnerabilidad de ejecución de secuencias de comandos en sitios cruzados (XSS) en group/members.php in Mahara v1.4.x anterior a v1.4.5 y v1.5.x anterior a v1.5.4 permite a atacantes remotos inyectar secuencias de comandos web o HTML a través vectores relacionados con artefact/file/ y un ficher... • http://www.debian.org/security/2012/dsa-2591 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2012-2351
https://notcve.org/view.php?id=CVE-2012-2351
12 Jul 2012 — The default configuration of the auth/saml plugin in Mahara before 1.4.2 sets the "Match username attribute to Remote username" option to false, which allows remote SAML IdP servers to spoof users of other SAML IdP servers by using the same internal username. La configuración por defecto del plugin auth/SAML en Mahara antes de v1.4.2 establece el atributo "Match Username to Remote Username" a falso, lo que permite falsificar usuarios de otros servidores a los servidores remotos SAML IdP utilizando el mismo ... • http://gitorious.org/mahara/mahara/commit/f07be6020e70fa8f53cd77fdcd63e7fd7ff8aaea • CWE-16: Configuration CWE-284: Improper Access Control CWE-287: Improper Authentication •

CVE-2011-4118
https://notcve.org/view.php?id=CVE-2011-4118
15 Nov 2011 — Mahara before 1.4.1, when MNet (aka the Moodle network feature) is used, allows remote authenticated users to gain privileges via a jump to an XMLRPC target. Mahara antes de v1.4.1, cuando se usa MNet (también conocido como Moodle network), permite a usuarios autenticados ganar privilegios a través de un salto a un objetivo XMLRPC • http://mahara.org/interaction/forum/topic.php?id=4138 • CWE-264: Permissions, Privileges, and Access Controls •