« Volver al listado

CVE-2019-9709

Estado: ModificadaMedia (5.4)—

An issue was discovered in Mahara 17.10 before 17.10.8, 18.04 before 18.04.4, and 18.10 before 18.10.1. The collection title is vulnerable to Cross Site Scripting (XSS) due to not escaping it when viewing the collection's SmartEvidence overview page (if that feature is turned on). This can be exploited by any logged-in user.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2019-9709",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 3.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:S/C:N/I:P/A:N",
          "authentication": "SINGLE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "LOW",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 6.8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.0",
          "baseScore": 5.4,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.7,
        "exploitabilityScore": 2.3
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2019-05-07T14:29:01.193",
  "references": [
    {
      "url": "https://bugs.launchpad.net/bugs/1819547",
      "tags": [
        "Issue Tracking",
        "Third Party Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://mahara.org/interaction/forum/topic.php?id=8446",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://bugs.launchpad.net/bugs/1819547",
      "tags": [
        "Issue Tracking",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://mahara.org/interaction/forum/topic.php?id=8446",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "An issue was discovered in Mahara 17.10 before 17.10.8, 18.04 before 18.04.4, and 18.10 before 18.10.1. The collection title is vulnerable to Cross Site Scripting (XSS) due to not escaping it when viewing the collection's SmartEvidence overview page (if that feature is turned on). This can be exploited by any logged-in user."
    },
    {
      "lang": "es",
      "value": "Fue encontrado un problema en Mahara  versión 17.10 anterior de 17.10.8, versión 18.04 anterior de 18.04.4 y versión 18.10 anterior de 18.10.1. El título collection es vulnerable a Cross Site Scripting (XSS) debido a que no escapa al ver la página de información general de collection's SmartEvidence (si esa función está activada). Esto puede ser explotado por cualquier usuario registrado."
    }
  ],
  "lastModified": "2026-06-17T02:44:12.860",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:mahara:mahara:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2DFA9054-9C40-4415-B723-732BBB7E8C85",
              "versionEndExcluding": "17.10.8",
              "versionStartIncluding": "17.10.0"
            },
            {
              "criteria": "cpe:2.3:a:mahara:mahara:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A60B16D5-4924-45E9-B71B-C8DF16C79360",
              "versionEndExcluding": "18.04.4",
              "versionStartIncluding": "18.04.0"
            },
            {
              "criteria": "cpe:2.3:a:mahara:mahara:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "00E63397-B5EF-485D-BA1A-6FDA3827C3AD",
              "versionEndExcluding": "18.10.1",
              "versionStartIncluding": "18.10.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}