Arbitrary Web Script Injection in Mahara TinyMCE Editor

Arbitrary Web Script Injection in Mahara TinyMCE Editor

CVE-2013-1426 · MEDIUM Severity

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Cross-site Scripting (XSS) in Mahara before 1.5.9 and 1.6.x before 1.6.4 allows remote attackers to inject arbitrary web script or HTML via the TinyMCE editor.

Learn more about our Web App Pen Testing.