CVE-2017-1000140: Mahara
Medium severity, CVSS 5.4. EPSS: 0.5% chance of exploitation in the next 30 days.
Mahara 1.8 before 1.8.7 and 1.9 before 1.9.5 and 1.10 before 1.10.3 and 15.04 before 15.04.0 are vulnerable to a maliciously created .xml file that can have its code executed when user tries to download the file.
Affected products
- Mahara Mahara: version 1.8 only; version 1.8.0 only; version 1.8.1 only; version 1.8.2 only; version 1.8.3 only; version 1.8.4 only; …
Published 2017-11-03. Last modified 2026-06-17.