cvedb.io
CVE-2017-14752
MEDIUM · CVSS 5.4
EPSS exploitation probability: 0%
Published 2017-10-31T18:29:00.313 · Last modified 2026-06-17T01:06:43.710

Summary

Mahara 15.04 before 15.04.15, 16.04 before 16.04.9, 16.10 before 16.10.6, and 17.04 before 17.04.4 are vulnerable to a user submitting a potential dangerous payload, e.g., XSS code, to be saved as their first name, last name, or display name in the profile fields that can cause issues such as escalation of privileges or unknown execution of malicious code when replying to messages in Mahara.

Affected products

mahara — mahara

Does this affect you?

Add your gear to cvedb and we'll alert you only when mahara ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.