Mahara before 20.10.5, 21.04.4, 21.10.2, and 22.04.0 allows stored XSS when a particular Cascading Style Sheets (CSS) class for embedly is used, and JavaScript code is constructed to perform an action.
2022-04-28T16:15:08.500
2024-11-21T06:59:21.233
Modified
CVSSv3.1: 5.4 (MEDIUM)
AV:N/AC:M/Au:S/C:N/I:P/A:N
6.8
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | mahara | mahara | < 20.10.5 | Yes |
Application | mahara | mahara | < 21.04.4 | Yes |
Application | mahara | mahara | < 21.10.2 | Yes |
Application | mahara | mahara | 22.04.0 | Yes |