Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Cross-site scripting (XSS) vulnerability in Mahara 1.2.x before 1.2.7 and 1.3.x before 1.3.4 allows remote attackers to inject arbitrary web script or HTML via the Pieforms select box.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Mahara跨站脚本攻击漏洞
Vulnerability Description
Catalyst Mahara是新西兰Catalyst IT公司的一套社交网络系统。该系统包含博客、履历表生成器、文件管理器等。 Mahara 1.2.7之前的1.2.x版本和1.3.4之前的1.3.x版本中存在跨站脚本攻击漏洞。某些Pieform选择框选项的输入,还没有经过正确过滤就显示给用户。远程攻击者可利用此漏洞注入任意web脚本或HTML。当浏览恶意数据时,在受影响站点内容的用户浏览器会话中的这些代码就会得到执行。
CVSS Information
N/A
Vulnerability Type
N/A