VYPR
Unrated severityNVD Advisory· Published May 13, 2011· Updated Apr 29, 2026

CVE-2011-1405

CVE-2011-1405

Description

Cross-site scripting (XSS) vulnerability in Mahara before 1.3.6 allows remote authenticated users to inject arbitrary web script or HTML via vectors associated with HTML e-mail messages, related to artefact/comment/lib.php and interaction/forum/lib.php.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Mahara before 1.3.6 allows XSS via HTML emails; authenticated users can inject arbitrary web script or HTML in forum posts and view feedback notifications.

Vulnerability

A cross-site scripting (XSS) vulnerability exists in Mahara versions prior to 1.3.6. The issue resides in the HTML email handling code in artefact/comment/lib.php and interaction/forum/lib.php. When the application sends email notifications for forum posts and view feedback, it includes the message body in both HTML and plain-text formats. The HTML version does not properly escape user-supplied content, allowing injection of arbitrary web script or HTML. The bug was reported in the Mahara launchpad tracker and fixed in the 1.3.6 release [2][3].

Exploitation

An authenticated user can exploit this vulnerability by submitting a forum post or a view feedback comment containing malicious HTML or JavaScript. The system then sends an HTML email notification to other users (including potentially administrators) that includes the attacker's payload. No special privileges beyond a standard authenticated account are required; the attacker simply posts content that triggers the email notification. The exploit is triggered when the recipient views the HTML email in a vulnerable email client or webmail interface [1][2].

Impact

Successful exploitation allows an authenticated attacker to execute arbitrary web script in the context of a victim's email reader. This can lead to disclosure of sensitive information, session hijacking, or other client-side attacks within the scope of the email client. The impact is limited to users who receive and view the HTML email notifications; the vulnerable code path does not directly affect the Mahara web application itself beyond the email generation [1][2].

Mitigation

Users should upgrade to Mahara version 1.3.6 (released in March 2011) or later. For those running version 1.2.x, upgrade to 1.2.9. Users on version 1.4.x can upgrade to 1.4.0. All these releases contain the fix for this XSS issue. No workaround is available for unpatched versions. Administrators can also consider disabling HTML email notifications if upgrading is not immediately possible [2][3].

AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

66
  • cpe:2.3:a:mahara:mahara:*:*:*:*:*:*:*:*+ 65 more
    • cpe:2.3:a:mahara:mahara:*:*:*:*:*:*:*:*range: <=1.3.5
    • cpe:2.3:a:mahara:mahara:0.9.0:*:*:*:*:*:*:*
    • cpe:2.3:a:mahara:mahara:0.9.1:*:*:*:*:*:*:*
    • cpe:2.3:a:mahara:mahara:0.9.2:*:*:*:*:*:*:*
    • cpe:2.3:a:mahara:mahara:1.0.0:*:*:*:*:*:*:*
    • cpe:2.3:a:mahara:mahara:1.0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:mahara:mahara:1.0.10:*:*:*:*:*:*:*
    • cpe:2.3:a:mahara:mahara:1.0.11:*:*:*:*:*:*:*
    • cpe:2.3:a:mahara:mahara:1.0.12:*:*:*:*:*:*:*
    • cpe:2.3:a:mahara:mahara:1.0.13:*:*:*:*:*:*:*
    • cpe:2.3:a:mahara:mahara:1.0.14:*:*:*:*:*:*:*
    • cpe:2.3:a:mahara:mahara:1.0.15:*:*:*:*:*:*:*
    • cpe:2.3:a:mahara:mahara:1.0.2:*:*:*:*:*:*:*
    • cpe:2.3:a:mahara:mahara:1.0.3:*:*:*:*:*:*:*
    • cpe:2.3:a:mahara:mahara:1.0.4:*:*:*:*:*:*:*
    • cpe:2.3:a:mahara:mahara:1.0.5:*:*:*:*:*:*:*
    • cpe:2.3:a:mahara:mahara:1.0.6:*:*:*:*:*:*:*
    • cpe:2.3:a:mahara:mahara:1.0.7:*:*:*:*:*:*:*
    • cpe:2.3:a:mahara:mahara:1.0.8:*:*:*:*:*:*:*
    • cpe:2.3:a:mahara:mahara:1.0.9:*:*:*:*:*:*:*
    • cpe:2.3:a:mahara:mahara:1.1:*:*:*:*:*:*:*
    • cpe:2.3:a:mahara:mahara:1.1.0:*:*:*:*:*:*:*
    • cpe:2.3:a:mahara:mahara:1.1.0:alpha1:*:*:*:*:*:*
    • cpe:2.3:a:mahara:mahara:1.1.0:alpha2:*:*:*:*:*:*
    • cpe:2.3:a:mahara:mahara:1.1.0:alpha3:*:*:*:*:*:*
    • cpe:2.3:a:mahara:mahara:1.1.0:beta1:*:*:*:*:*:*
    • cpe:2.3:a:mahara:mahara:1.1.0:beta2:*:*:*:*:*:*
    • cpe:2.3:a:mahara:mahara:1.1.0:beta3:*:*:*:*:*:*
    • cpe:2.3:a:mahara:mahara:1.1.0:beta4:*:*:*:*:*:*
    • cpe:2.3:a:mahara:mahara:1.1.0:rc1:*:*:*:*:*:*
    • cpe:2.3:a:mahara:mahara:1.1.0:rc2:*:*:*:*:*:*
    • cpe:2.3:a:mahara:mahara:1.1.1:*:*:*:*:*:*:*
    • cpe:2.3:a:mahara:mahara:1.1.2:*:*:*:*:*:*:*
    • cpe:2.3:a:mahara:mahara:1.1.3:*:*:*:*:*:*:*
    • cpe:2.3:a:mahara:mahara:1.1.4:*:*:*:*:*:*:*
    • cpe:2.3:a:mahara:mahara:1.1.5:*:*:*:*:*:*:*
    • cpe:2.3:a:mahara:mahara:1.1.6:*:*:*:*:*:*:*
    • cpe:2.3:a:mahara:mahara:1.1.7:*:*:*:*:*:*:*
    • cpe:2.3:a:mahara:mahara:1.1.8:*:*:*:*:*:*:*
    • cpe:2.3:a:mahara:mahara:1.1.9:*:*:*:*:*:*:*
    • cpe:2.3:a:mahara:mahara:1.2.0:*:*:*:*:*:*:*
    • cpe:2.3:a:mahara:mahara:1.2.0:alpha1:*:*:*:*:*:*
    • cpe:2.3:a:mahara:mahara:1.2.0:alpha2:*:*:*:*:*:*
    • cpe:2.3:a:mahara:mahara:1.2.0:alpha3:*:*:*:*:*:*
    • cpe:2.3:a:mahara:mahara:1.2.0:beta1:*:*:*:*:*:*
    • cpe:2.3:a:mahara:mahara:1.2.0:beta2:*:*:*:*:*:*
    • cpe:2.3:a:mahara:mahara:1.2.0:beta3:*:*:*:*:*:*
    • cpe:2.3:a:mahara:mahara:1.2.0:beta4:*:*:*:*:*:*
    • cpe:2.3:a:mahara:mahara:1.2.0:rc1:*:*:*:*:*:*
    • cpe:2.3:a:mahara:mahara:1.2.1:*:*:*:*:*:*:*
    • cpe:2.3:a:mahara:mahara:1.2.2:*:*:*:*:*:*:*
    • cpe:2.3:a:mahara:mahara:1.2.3:*:*:*:*:*:*:*
    • cpe:2.3:a:mahara:mahara:1.2.4:*:*:*:*:*:*:*
    • cpe:2.3:a:mahara:mahara:1.2.5:*:*:*:*:*:*:*
    • cpe:2.3:a:mahara:mahara:1.2.6:*:*:*:*:*:*:*
    • cpe:2.3:a:mahara:mahara:1.3.0:*:*:*:*:*:*:*
    • cpe:2.3:a:mahara:mahara:1.3.0:beta1:*:*:*:*:*:*
    • cpe:2.3:a:mahara:mahara:1.3.0:beta2:*:*:*:*:*:*
    • cpe:2.3:a:mahara:mahara:1.3.0:beta3:*:*:*:*:*:*
    • cpe:2.3:a:mahara:mahara:1.3.0:beta4:*:*:*:*:*:*
    • cpe:2.3:a:mahara:mahara:1.3.0:rc1:*:*:*:*:*:*
    • cpe:2.3:a:mahara:mahara:1.3.1:*:*:*:*:*:*:*
    • cpe:2.3:a:mahara:mahara:1.3.2:*:*:*:*:*:*:*
    • cpe:2.3:a:mahara:mahara:1.3.3:*:*:*:*:*:*:*
    • cpe:2.3:a:mahara:mahara:1.3.4:*:*:*:*:*:*:*
    • (no CPE)range: <1.3.6

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

6

News mentions

0

No linked articles in our index yet.