Medium severity6.1NVD Advisory· Published Nov 7, 2019· Updated Jun 16, 2026
CVE-2013-1426
CVE-2013-1426
Description
Cross-site Scripting (XSS) in Mahara before 1.5.9 and 1.6.x before 1.6.4 allows remote attackers to inject arbitrary web script or HTML via the TinyMCE editor.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:mahara:mahara:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:mahara:mahara:*:*:*:*:*:*:*:*range: <1.5.9
- (no CPE)range: <1.5.9, <1.6.4
- (no CPE)range: 1.5.9
Patches
Vulnerability mechanics
References
3- mahara.org/interaction/forum/topic.phpnvdPatchVendor Advisory
- bugs.launchpad.net/mahara/+bug/1153423nvdIssue TrackingThird Party Advisory
- security-tracker.debian.org/tracker/CVE-2013-1426nvdThird Party Advisory
News mentions
0No linked articles in our index yet.