296,854
Total vulnerabilities in the database
Mahara 1.4.x before 1.4.5 and 1.5.x before 1.5.4 allows remote attackers to conduct clickjacking attacks to delete arbitrary users and bypass CSRF protection via account/delete.php.
| Software | From | Fixed in |
|---|---|---|
| mahara / mahara | 1.4-rc2 | 1.4-rc2.x |
| mahara / mahara | 1.4.0 | 1.4.0.x |
| mahara / mahara | 1.4.2 | 1.4.2.x |
| mahara / mahara | 1.4-rc4 | 1.4-rc4.x |
| mahara / mahara | 1.4-rc3 | 1.4-rc3.x |
| mahara / mahara | 1.4.4 | 1.4.4.x |
| mahara / mahara | 1.4.3 | 1.4.3.x |
| mahara / mahara | 1.4-rc1 | 1.4-rc1.x |
| mahara / mahara | 1.4.1 | 1.4.1.x |
| mahara / mahara | 1.5-rc1 | 1.5-rc1.x |
| mahara / mahara | 1.5.2 | 1.5.2.x |
| mahara / mahara | 1.5.3 | 1.5.3.x |
| mahara / mahara | 1.5.0 | 1.5.0.x |
| mahara / mahara | 1.5-rc2 | 1.5-rc2.x |
| mahara / mahara | 1.5.1 | 1.5.1.x |