Mahara 1.10 before 1.10.0 and 15.04 before 15.04.0 are vulnerable to possible cross site scripting when dragging/dropping files into a collection if the file has Javascript code in its title.
{
"versions": [
{
"introduced": "0"
},
{
"last_affected": "1.10-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "15.04-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "15.04-rc2"
}
]
}