Логотип exploitDog
bind:CVE-2018-6182
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2018-6182

Количество 3

Количество 3

nvd логотип

CVE-2018-6182

почти 8 лет назад

Mahara 16.10 before 16.10.9 and 17.04 before 17.04.7 and 17.10 before 17.10.4 are vulnerable to bad input when TinyMCE is bypassed by POST packages. Therefore, Mahara should not rely on TinyMCE's code stripping alone but also clean input on the server / PHP side as one can create own packets of POST data containing bad content with which to hit the server.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2018-6182

почти 8 лет назад

Mahara 16.10 before 16.10.9 and 17.04 before 17.04.7 and 17.10 before ...

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-j7qh-wjjv-qxg8

больше 3 лет назад

Mahara 16.10 before 16.10.9 and 17.04 before 17.04.7 and 17.10 before 17.10.4 are vulnerable to bad input when TinyMCE is bypassed by POST packages. Therefore, Mahara should not rely on TinyMCE's code stripping alone but also clean input on the server / PHP side as one can create own packets of POST data containing bad content with which to hit the server.

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2018-6182

Mahara 16.10 before 16.10.9 and 17.04 before 17.04.7 and 17.10 before 17.10.4 are vulnerable to bad input when TinyMCE is bypassed by POST packages. Therefore, Mahara should not rely on TinyMCE's code stripping alone but also clean input on the server / PHP side as one can create own packets of POST data containing bad content with which to hit the server.

CVSS3: 6.1
0%
Низкий
почти 8 лет назад
debian логотип
CVE-2018-6182

Mahara 16.10 before 16.10.9 and 17.04 before 17.04.7 and 17.10 before ...

CVSS3: 6.1
0%
Низкий
почти 8 лет назад
github логотип
GHSA-j7qh-wjjv-qxg8

Mahara 16.10 before 16.10.9 and 17.04 before 17.04.7 and 17.10 before 17.10.4 are vulnerable to bad input when TinyMCE is bypassed by POST packages. Therefore, Mahara should not rely on TinyMCE's code stripping alone but also clean input on the server / PHP side as one can create own packets of POST data containing bad content with which to hit the server.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу