DSA-1736-1 mahara -- insufficient input sanitisingID: oval:org.secpod.oval:def:600442 | Date: (C)2011-05-13 (M)2022-10-10 |
Class: PATCH | Family: unix |
It was discovered that mahara, an electronic portfolio, weblog, and resume builder, is prone to cross-site scripting attacks, which allows the injection of arbitrary Java or HTML code. For the stable distribution , this problem has been fixed in version 1.0.4-4+lenny1. The oldstable distribution does not contain mahara. For the testing distribution and the unstable distribution , this problem will be fixed soon. We recommend that you upgrade your mahara package.