Mahara before 25.04.2 and 24.04.11 are vulnerable to displaying results that can trigger XSS via a malicious search query string. This occurs in the 'search site' feature when using the Elasticsearch7 search plugin. The Elasticsearch function does not properly sanitize input in the query parameter.
Metrics
Affected Vendors & Products
References
History
Fri, 24 Apr 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 | |
| Metrics |
cvssV3_1
|
Fri, 24 Apr 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Mahara before 25.04.2 and 24.04.11 are vulnerable to displaying results that can trigger XSS via a malicious search query string. This occurs in the 'search site' feature when using the Elasticsearch7 search plugin. The Elasticsearch function does not properly sanitize input in the query parameter. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2026-04-24T00:00:00.000Z
Updated: 2026-04-24T15:03:27.399Z
Reserved: 2025-10-03T00:00:00.000Z
Link: CVE-2025-61872
Updated: 2026-04-24T15:02:03.716Z
Status : Deferred
Published: 2026-04-24T15:16:25.320
Modified: 2026-04-24T17:54:36.243
Link: CVE-2025-61872
No data.