Mahara Multiple Cross Site Scripting and HTML Injection Vulnerabilities
BID:54776
Info
Mahara Multiple Cross Site Scripting and HTML Injection Vulnerabilities
| Bugtraq ID: | 54776 |
| Class: | Input Validation Error |
| CVE: |
CVE-2012-2237 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 02 2012 12:00AM |
| Updated: | Sep 07 2012 09:39PM |
| Credit: | Vendor and Emanuel Bronshtein. |
| Vulnerable: |
Mahara Mahara 1.4.1 Mahara Mahara 1.4 Mahara Mahara 1.3.6 Mahara Mahara 1.3.5 Mahara Mahara 1.3.4 Mahara Mahara 1.3.3 Mahara Mahara 1.2.4 Mahara Mahara 1.2.3 Mahara Mahara 1.3.2 Mahara Mahara 1.3.1 Mahara Mahara 1.3.0 Mahara Mahara 1.2.7 Mahara Mahara 1.2.6 Mahara Mahara 1.2.5 Mahara Mahara 1.2.2 Mahara Mahara 1.2.1 Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 |
| Not Vulnerable: | |
Discussion
Mahara Multiple Cross Site Scripting and HTML Injection Vulnerabilities
Mahara is prone to multiple cross-site scripting vulnerabilities and an HTML-injection vulnerability because it fails to properly sanitize user-supplied text.
Successful exploits will allow attacker-supplied HTML and script code to run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or control how the site is rendered to the user. Other attacks are also possible.
Mahara versions prior to 1.5.2 and prior to 1.4.3 are vulnerable.
Mahara is prone to multiple cross-site scripting vulnerabilities and an HTML-injection vulnerability because it fails to properly sanitize user-supplied text.
Successful exploits will allow attacker-supplied HTML and script code to run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or control how the site is rendered to the user. Other attacks are also possible.
Mahara versions prior to 1.5.2 and prior to 1.4.3 are vulnerable.
Exploit / POC
Mahara Multiple Cross Site Scripting and HTML Injection Vulnerabilities
An attacker can exploit these issues using a browser. To exploit a cross-site scripting vulnerability, the attacker will entice an unsuspecting user to visit a specially crafted URL.
The following exploit is available:
An attacker can exploit these issues using a browser. To exploit a cross-site scripting vulnerability, the attacker will entice an unsuspecting user to visit a specially crafted URL.
The following exploit is available:
Solution / Fix
Mahara Multiple Cross Site Scripting and HTML Injection Vulnerabilities
Solution:
Vendor updates are available. Please see the references for more information.
Solution:
Vendor updates are available. Please see the references for more information.
References
Mahara Multiple Cross Site Scripting and HTML Injection Vulnerabilities
References:
References:
- Mahara Homepage (Mahara)