Debian Security Advisory 1736-1 – It was discovered that mahara, an electronic portfolio, weblog, and resume builder, is prone to cross-site scripting attacks, which allows the injection of arbitrary Java or HTML code.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/75631/dsa-1736-1.txt
Source: https://packetstormsecurity.com/files/75631/Debian-Linux-Security-Advisory-1736-1.html

