CVE-2017-1000138: Mahara
Medium severity, CVSS 5.4. EPSS: 0.5% chance of exploitation in the next 30 days.
Mahara 1.10 before 1.10.0 and 15.04 before 15.04.0 are vulnerable to possible cross site scripting when dragging/dropping files into a collection if the file has Javascript code in its title.
Affected products
- Mahara Mahara: version 1.10 only; version 15.04 only
Published 2017-11-03. Last modified 2026-06-17.