Description
|
|
Multiple vulnerabilities have been identified in Mahara, which could be exploited by attackers to disclose sensitive information or gain elevated privileges.
The first issue is caused by an input validation error when processing the resume blocktype, which could allow cross site scripting attacks.
The second vulnerability is caused by insufficient access validation, which could allow an institution administrator to reset the password of the site administrator and gain his privileges.
|