DSA-1778-1 mahara -- insufficient input sanitizationID: oval:org.secpod.oval:def:600336 | Date: (C)2011-05-13 (M)2022-10-10 |
Class: PATCH | Family: unix |
It was discovered that mahara, an electronic portfolio, weblog, and resume builder, is prone to cross-site scripting attacks because of missing input sanitization of the introduction text field in user profiles and any text field in a user view. The oldstable distribution does not contain mahara. For the stable distribution , this problem has been fixed in version 1.0.4-4+lenny2. For the testing distribution , this problem will be fixed soon. For the unstable distribution , this problem has been fixed in version 1.1.3-1. We recommend that you upgrade your mahara packages.