CVE-2017-1000148

HIGH

Mahara <15.04.8, <15.10.4, <16.04.2 - Code Injection

Title source: llm

Description

Mahara 15.04 before 15.04.8 and 15.10 before 15.10.4 and 16.04 before 16.04.2 are vulnerable to PHP code execution as Mahara would pass portions of the XML through the PHP "unserialize()" function when importing a skin from an XML file.

Scores

CVSS v3 8.8
EPSS 0.0050
EPSS Percentile 65.9%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-502
Status draft

Affected Products (18)

mahara/mahara
mahara/mahara
mahara/mahara
mahara/mahara
mahara/mahara
mahara/mahara
mahara/mahara
mahara/mahara
mahara/mahara
mahara/mahara
mahara/mahara
mahara/mahara
mahara/mahara
mahara/mahara
mahara/mahara
... and 3 more

Timeline

Published Nov 03, 2017
Tracked Since Feb 18, 2026