Описание
An issue was discovered in Mahara 24.04 before 24.04.2 and 23.04 before 23.04.7. The About, Contact, and Help footer links can be set up to be vulnerable to Cross Site Scripting (XSS) due to not sanitising the values. These links can only be set up by an admin but are clickable by any logged-in person.
Ссылки
- Vendor Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 23.04.0 (включая) до 23.04.7 (исключая)Версия от 24.04.0 (включая) до 24.04.2 (включая)
Одно из
cpe:2.3:a:mahara:mahara:*:*:*:*:*:*:*:*
cpe:2.3:a:mahara:mahara:*:*:*:*:*:*:*:*
EPSS
Процентиль: 4%
0.00019
Низкий
6.1 Medium
CVSS3
Дефекты
CWE-79
Связанные уязвимости
CVSS3: 6.1
debian
6 месяцев назад
An issue was discovered in Mahara 24.04 before 24.04.2 and 23.04 befor ...
CVSS3: 6.1
github
6 месяцев назад
An issue was discovered in Mahara 24.04 before 24.04.2 and 23.04 before 23.04.7. The About, Contact, and Help footer links can be set up to be vulnerable to Cross Site Scripting (XSS) due to not sanitising the values. These links can only be set up by an admin but are clickable by any logged-in person.
EPSS
Процентиль: 4%
0.00019
Низкий
6.1 Medium
CVSS3
Дефекты
CWE-79