Логотип exploitDog
bind:CVE-2017-17454
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2017-17454

Количество 3

Количество 3

nvd логотип

CVE-2017-17454

почти 8 лет назад

Mahara 16.10 before 16.10.7 and 17.04 before 17.04.5 and 17.10 before 17.10.2 have a Cross Site Scripting (XSS) vulnerability when a user enters invalid UTF-8 characters. These are now going to be discarded in Mahara along with NULL characters and invalid Unicode characters. Mahara will also avoid direct $_GET and $_POST usage where possible, and instead use param_exists() and the correct param_*() function to fetch the expected value.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2017-17454

почти 8 лет назад

Mahara 16.10 before 16.10.7 and 17.04 before 17.04.5 and 17.10 before ...

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-6q4p-5jg7-p386

больше 3 лет назад

Mahara 16.10 before 16.10.7 and 17.04 before 17.04.5 and 17.10 before 17.10.2 have a Cross Site Scripting (XSS) vulnerability when a user enters invalid UTF-8 characters. These are now going to be discarded in Mahara along with NULL characters and invalid Unicode characters. Mahara will also avoid direct $_GET and $_POST usage where possible, and instead use param_exists() and the correct param_*() function to fetch the expected value.

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2017-17454

Mahara 16.10 before 16.10.7 and 17.04 before 17.04.5 and 17.10 before 17.10.2 have a Cross Site Scripting (XSS) vulnerability when a user enters invalid UTF-8 characters. These are now going to be discarded in Mahara along with NULL characters and invalid Unicode characters. Mahara will also avoid direct $_GET and $_POST usage where possible, and instead use param_exists() and the correct param_*() function to fetch the expected value.

CVSS3: 5.4
0%
Низкий
почти 8 лет назад
debian логотип
CVE-2017-17454

Mahara 16.10 before 16.10.7 and 17.04 before 17.04.5 and 17.10 before ...

CVSS3: 5.4
0%
Низкий
почти 8 лет назад
github логотип
GHSA-6q4p-5jg7-p386

Mahara 16.10 before 16.10.7 and 17.04 before 17.04.5 and 17.10 before 17.10.2 have a Cross Site Scripting (XSS) vulnerability when a user enters invalid UTF-8 characters. These are now going to be discarded in Mahara along with NULL characters and invalid Unicode characters. Mahara will also avoid direct $_GET and $_POST usage where possible, and instead use param_exists() and the correct param_*() function to fetch the expected value.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу