Mahara 1.10 before 1.10.0 and 15.04 before 15.04.0 are vulnerable to possible cross site scripting when dragging/dropping files into a collection if the file has Javascript code in its title.
{
"cpe": [
"cpe:2.3:a:mahara:mahara:1.10:rc1:*:*:*:*:*:*",
"cpe:2.3:a:mahara:mahara:15.04:rc1:*:*:*:*:*:*",
"cpe:2.3:a:mahara:mahara:15.04:rc2:*:*:*:*:*:*"
],
"source": "CPE_STRING",
"extracted_events": [
{
"introduced": "1.10-rc1"
},
{
"last_affected": "1.10-rc1"
},
{
"introduced": "15.04-rc1"
},
{
"last_affected": "15.04-rc1"
},
{
"introduced": "15.04-rc2"
},
{
"last_affected": "15.04-rc2"
}
]
}