User-Submitted Payload Vulnerability in Mahara

User-Submitted Payload Vulnerability in Mahara

CVE-2017-9551 · MEDIUM Severity

AV:N/AC:M/AU:N/C:N/I:P/A:N

Mahara 15.04 before 15.04.14 and 16.04 before 16.04.8 and 16.10 before 16.10.5 and 17.04 before 17.04.3 are vulnerable to a user submitting potential dangerous payload, e.g. XSS code, to be saved as their name in the usr_registration table. The values are then emailed to the the user and administrator and if accepted become part of the new user's account.

Learn more about our User Device Pen Test.