Mahara 1.4.x before 1.4.4 and 1.5.x before 1.5.3 allows remote attackers to read arbitrary files or create TCP connections via an XML external entity (XXE) injection attack, as demonstrated by reading config.php.
References
Link | Resource |
---|---|
http://www.debian.org/security/2012/dsa-2591 | Mailing List |
https://bugs.launchpad.net/mahara/+bug/1047111 | Issue Tracking Patch |
https://mahara.org/interaction/forum/topic.php?id=4869 | Vendor Advisory |
Configurations
History
No history.
Information
Published : 2012-11-24 20:55
Updated : 2024-02-15 03:19
NVD link : CVE-2012-2239
Mitre link : CVE-2012-2239
CVE.ORG link : CVE-2012-2239
JSON object : View
Products Affected
mahara
- mahara
debian
- debian_linux
CWE
CWE-611
Improper Restriction of XML External Entity Reference