Vulnerability Description
An issue was discovered in Mahara 24.04 before 24.04.2 and 23.04 before 23.04.7. The About, Contact, and Help footer links can be set up to be vulnerable to Cross Site Scripting (XSS) due to not sanitising the values. These links can only be set up by an admin but are clickable by any logged-in person.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mahara | Mahara | >= 23.04.0, < 23.04.7 |
Related Weaknesses (CWE)
References
- https://mahara.org/interaction/forum/topic.php?id=9546Vendor Advisory
- https://mahara.org/interaction/forum/view.php?id=43Vendor Advisory
FAQ
What is CVE-2024-39923?
CVE-2024-39923 is a vulnerability with a CVSS score of 6.1 (MEDIUM). An issue was discovered in Mahara 24.04 before 24.04.2 and 23.04 before 23.04.7. The About, Contact, and Help footer links can be set up to be vulnerable to Cross Site Scripting (XSS) due to not sanit...
How severe is CVE-2024-39923?
CVE-2024-39923 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-39923?
Check the references section above for vendor advisories and patch information. Affected products include: Mahara Mahara.