Debian Linux Security Advisory 2206-1 – Two security vulnerabilities have been discovered in Mahara, a fully featured electronic portfolio, weblog, resume builder and social networking system. A security review commissioned by a Mahara user discovered that Mahara processes unsanitized input which can lead to cross-site scripting (XSS). Mahara Developers discovered that Mahara doesn’t check the session key under certain circumstances which can be exploited as cross-site request forgery (CSRF) and can lead to the deletion of blogs.
Source: Debian Security Advisory 2206-1




