| Description: | It was discovered that mahara, an electronic portfolio, weblog, and resume builder, is prone to cross-site scripting attacks, which allows the injection of arbitrary Java or HTML code. For the stable distribution, this problem has been fixed in version 1.0.4-4+lenny1. The oldstable distribution does not contain mahara. For the testing distribution and the unstable distribution, this problem will be fixed soon. We recommend that you upgrade your mahara package. |