« Volver al listado

CVE-2017-1000146

Estado: ModificadaMedia (5.4)—

Mahara 1.9 before 1.9.7 and 1.10 before 1.10.5 and 15.04 before 15.04.2 are vulnerable to the arbitrary execution of Javascript in the browser of a logged-in user because the title of the portfolio page was not being properly escaped in the AJAX script that updates the Add/remove watchlist link on artefact detail pages.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2017-1000146",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 3.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:S/C:N/I:P/A:N",
          "authentication": "SINGLE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "LOW",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 6.8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.0",
          "baseScore": 5.4,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.7,
        "exploitabilityScore": 2.3
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2017-11-03T18:29:00.760",
  "references": [
    {
      "url": "https://bugs.launchpad.net/mahara/+bug/1472439",
      "tags": [
        "Exploit",
        "Issue Tracking",
        "Patch",
        "Third Party Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://bugs.launchpad.net/mahara/+bug/1472439",
      "tags": [
        "Exploit",
        "Issue Tracking",
        "Patch",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Mahara 1.9 before 1.9.7 and 1.10 before 1.10.5 and 15.04 before 15.04.2 are vulnerable to the arbitrary execution of Javascript in the browser of a logged-in user because the title of the portfolio page was not being properly escaped in the AJAX script that updates the Add/remove watchlist link on artefact detail pages."
    },
    {
      "lang": "es",
      "value": "Mahara, en versiones 1.9 anteriores a la 1.9.7, versiones 1.10 anteriores a la 1.10.5 y versiones 15.04 anteriores a la 15.04.2, es vulnerable a la ejecución arbitraria de código JavaScript en el navegador de un usuario que haya iniciado sesión, debido a que el título del portfolio no se escapó correctamente en el script AJAX que actualiza el enlace Add/remove (Añadir/eliminar) de la lista de actividades en páginas de detalles de artefactos."
    }
  ],
  "lastModified": "2026-06-17T00:58:49.293",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:mahara:mahara:1.9:rc1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9375A9FA-C9B9-4406-937E-1FE1EC1EC3EC"
            },
            {
              "criteria": "cpe:2.3:a:mahara:mahara:1.9.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "03B93CE4-1D7F-49AF-AC56-8DFF01609099"
            },
            {
              "criteria": "cpe:2.3:a:mahara:mahara:1.9.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "89FE6330-10AD-4B30-AF0A-71635AB99B3F"
            },
            {
              "criteria": "cpe:2.3:a:mahara:mahara:1.9.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A5F4BFE6-A72F-4FAB-B975-EF1878767595"
            },
            {
              "criteria": "cpe:2.3:a:mahara:mahara:1.9.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8D937990-6958-4CD6-B976-E23C20567559"
            },
            {
              "criteria": "cpe:2.3:a:mahara:mahara:1.9.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A3852023-B803-418C-BA1D-9545C9FDC44B"
            },
            {
              "criteria": "cpe:2.3:a:mahara:mahara:1.9.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C8531F69-D7E5-403D-877C-6360C87F9C6D"
            },
            {
              "criteria": "cpe:2.3:a:mahara:mahara:1.9.6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A6C68FBF-5176-4FE9-BAEF-43AE316F4B00"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:mahara:mahara:1.10:rc1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1AF92381-863A-4D44-84B3-6116B15A6FD8"
            },
            {
              "criteria": "cpe:2.3:a:mahara:mahara:1.10.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5EDFBD79-ECF1-4AB2-8AA9-93E001AF5749"
            },
            {
              "criteria": "cpe:2.3:a:mahara:mahara:1.10.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "23092107-1709-43B2-AC94-3A53474CBEFB"
            },
            {
              "criteria": "cpe:2.3:a:mahara:mahara:1.10.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D5925E46-8A92-4A67-A8F6-7DF05C34BB55"
            },
            {
              "criteria": "cpe:2.3:a:mahara:mahara:1.10.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C4A2AF4C-CF93-458D-9FBF-B89BF5425BD9"
            },
            {
              "criteria": "cpe:2.3:a:mahara:mahara:1.10.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3BBAB23C-F0F7-4267-8803-9B8ED17145B0"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:mahara:mahara:15.04:rc1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DCE2F6EE-06BE-4665-BA7B-AB6C97DAE02D"
            },
            {
              "criteria": "cpe:2.3:a:mahara:mahara:15.04:rc2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "313A5DDA-204F-4ED3-BE22-FA0D8A239BC7"
            },
            {
              "criteria": "cpe:2.3:a:mahara:mahara:15.04.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6932E7F9-BA51-4099-8987-8944E0284B7B"
            },
            {
              "criteria": "cpe:2.3:a:mahara:mahara:15.04.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "022D7031-54EF-484C-B076-15C4342532E3"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}