Cross-site scripting (XSS) vulnerability in group/members.php in Mahara 1.5.x before 1.5.7 and 1.6.x before 1.6.2 allows remote attackers to inject arbitrary web script or HTML via the query parameter.
https://mahara.org/interaction/forum/topic.php?id=5076
https://bugs.launchpad.net/mahara/+bug/1079498