In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, certain tag syntax could be used for XSS, such as via a SCRIPT element.
2021-11-02T22:15:09.067
2024-11-21T06:28:57.037
Modified
CVSSv3.1: 5.4 (MEDIUM)
AV:N/AC:M/Au:S/C:N/I:P/A:N
6.8
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | mahara | mahara | < 20.04.5 | Yes |
Application | mahara | mahara | < 20.10.3 | Yes |
Application | mahara | mahara | < 21.04.2 | Yes |