Mahara CSV domain XSS Vulnerability
Release date:
Updated on:
Affected Systems:
Mahara 1.5.x
Mahara 1.4.x
Mahara 1.2
Description:
--------------------------------------------------------------------------------
CVE (CAN) ID: CVE-2012-6037
Mahara is an open-source electronic folder, network log, resume generator, and social networking system.
Mahara 1.4.x (earlier than 1.4.5), 1.5.x (earlier than 1.5.4), and 1.2 have Multiple XSS vulnerabilities, the CSV fields in unknown fields are not correctly processed in error messages in bulk user, group, and group member upload functions, allowing remote attackers to inject arbitrary Web scripts or HTML.
<* Source: vendor
Link: http://web.nvd.nist.gov/view/vuln/detail? VulnId = CVE-2012-6037
Https://mahara.org/interaction/forum/topic.php? Id = 4937
*>
Test method:
--------------------------------------------------------------------------------
Alert
The following procedures (methods) may be offensive and are intended only for security research and teaching. Users are at your own risk!
Vendor () provides the following test methods:
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Mahara
------
Https://bugs.launchpad.net/mahara/+bug/1055232