CVE-2018-6182

Source
https://nvd.nist.gov/vuln/detail/CVE-2018-6182
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2018-6182.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2018-6182
Published
2018-04-09T20:29:00Z
Modified
2025-01-08T05:22:26.180606Z
Severity
  • 6.1 (Medium) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

Mahara 16.10 before 16.10.9 and 17.04 before 17.04.7 and 17.10 before 17.10.4 are vulnerable to bad input when TinyMCE is bypassed by POST packages. Therefore, Mahara should not rely on TinyMCE's code stripping alone but also clean input on the server / PHP side as one can create own packets of POST data containing bad content with which to hit the server.

References

Affected packages

Git / github.com/maharaproject/mahara

Affected ranges

Type
GIT
Repo
https://github.com/maharaproject/mahara
Events

Affected versions

16.*

16.10.0_RELEASE
16.10.1_RELEASE
16.10.2_RELEASE
16.10.3_RELEASE
16.10.4_RELEASE
16.10.5_RELEASE
16.10.6_RELEASE
16.10.7_RELEASE
16.10.8_RELEASE