← Zuruck zu CVEs
CVE-2025-61872
MEDIUM6.1
Beschreibung
Mahara before 25.04.2 and 24.04.11 are vulnerable to displaying results that can trigger XSS via a malicious search query string. This occurs in the 'search site' feature when using the Elasticsearch7 search plugin. The Elasticsearch function does not properly sanitize input in the query parameter.
CVE Details
CVSS v3.1 Bewertung6.1
SchweregradMEDIUM
CVSS VektorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
AngriffsvektorNETWORK
KomplexitatLOW
Erforderliche PrivilegienNONE
BenutzerinteraktionREQUIRED
Veroffentlicht4/24/2026
Zuletzt geandert4/24/2026
Quellenvd
Honeypot-Sichtungen0
Schwachen (CWE)
CWE-79
Referenzen
https://mahara.org(cve@mitre.org)
https://mahara.org/interaction/forum/topic.php?id=9851(cve@mitre.org)
IOC Korrelationen
Keine Korrelationen erfasst
This product uses data from the NVD API but is not endorsed or certified by the NVD.