Vulnerability Description
Mahara 15.04 before 15.04.15, 16.04 before 16.04.9, 16.10 before 16.10.6, and 17.04 before 17.04.4 are vulnerable to a user submitting a potential dangerous payload, e.g., XSS code, to be saved as their first name, last name, or display name in the profile fields that can cause issues such as escalation of privileges or unknown execution of malicious code when replying to messages in Mahara.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mahara | Mahara | 15.04 |
Related Weaknesses (CWE)
References
- https://bugs.launchpad.net/mahara/+bug/1719491Issue TrackingPatchThird Party Advisory
- https://bugs.launchpad.net/mahara/+bug/1719491Issue TrackingPatchThird Party Advisory
FAQ
What is CVE-2017-14752?
CVE-2017-14752 is a vulnerability with a CVSS score of 5.4 (MEDIUM). Mahara 15.04 before 15.04.15, 16.04 before 16.04.9, 16.10 before 16.10.6, and 17.04 before 17.04.4 are vulnerable to a user submitting a potential dangerous payload, e.g., XSS code, to be saved as the...
How severe is CVE-2017-14752?
CVE-2017-14752 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-14752?
Check the references section above for vendor advisories and patch information. Affected products include: Mahara Mahara.