CVE-2017-1000149: Mahara

Medium severity, CVSS 5.4. EPSS: 0.5% chance of exploitation in the next 30 days.

Mahara 1.10 before 1.10.9 and 15.04 before 15.04.6 and 15.10 before 15.10.2 are vulnerable to XSS due to window.opener (target="_blank" and window.open())

Affected products

  • Mahara Mahara: version 15.10 only; version 15.10.0 only; version 15.10.1 only; version 1.10 only; version 1.10.0 only; version 1.10.1 only; …

Published 2017-11-03. Last modified 2026-06-17.