← Back

CVE-2024-39923

nvd nist
Published: Aug 25, 2025Modified: Jun 17, 2026

JSON object

Loading...
6.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

An issue was discovered in Mahara 24.04 before 24.04.2 and 23.04 before 23.04.7. The About, Contact, and Help footer links can be set up to be vulnerable to Cross Site Scripting (XSS) due to not sanitising the values. These links can only be set up by an admin but are clickable by any logged-in person.

Affected (2)

Products: Mahara: Mahara
1 product
Mahara
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Mahara
From 23.04.0 to 23.04.7
From 24.04.0 to 24.04.2

References (2)

Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Vendor Advisory

Timeline

No history available yet.