Mahara before 25.04.2 and 24.04.11 are vulnerable to displaying results that can trigger XSS via a malicious search query string. This occurs in the 'search site' feature when using the Elasticsearch7 search plugin. The Elasticsearch function does not properly sanitize input in the query parameter.
Metrics
Affected Vendors & Products
References
History
Tue, 28 Apr 2026 07:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Mahara XSS Vulnerability via Malicious Search Query in Elasticsearch7 Plugin |
Mon, 27 Apr 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mahara
Mahara mahara |
|
| Vendors & Products |
Mahara
Mahara mahara |
Fri, 24 Apr 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 | |
| Metrics |
cvssV3_1
|
Fri, 24 Apr 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Mahara before 25.04.2 and 24.04.11 are vulnerable to displaying results that can trigger XSS via a malicious search query string. This occurs in the 'search site' feature when using the Elasticsearch7 search plugin. The Elasticsearch function does not properly sanitize input in the query parameter. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2026-04-24T00:00:00.000Z
Updated: 2026-04-24T15:03:27.399Z
Reserved: 2025-10-03T00:00:00.000Z
Link: CVE-2025-61872
Updated: 2026-04-24T15:02:03.716Z
Status : Deferred
Published: 2026-04-24T15:16:25.320
Modified: 2026-04-24T17:54:36.243
Link: CVE-2025-61872
No data.
ReportizFlow