PT-2026-28480 · Sakai · Sakai

CVE-2026-33402

·

Publicado

2026-03-26

·

Atualizado

2026-03-27

CVSS v3.1

6.1

Média

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Sakai versions 23.0 through 23.4 Sakai versions 25.0 through 25.1
Description Sakai is a Collaboration and Learning Environment (CLE). Group titles and descriptions can contain cross-site scripting scripts. The issue affects versions 23.0 through 23.4 and 25.0 through 25.1. As a workaround, the SAKAI SITE GROUP table can be checked for titles and descriptions containing malicious scripts.
Recommendations Update to Sakai version 23.5 or later. Update to Sakai version 25.2 or later. As a workaround, check the SAKAI SITE GROUP table for titles and descriptions that contain potentially malicious scripts.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-33402
GHSA-6G62-3898-HPVM

Produtos afetados

Sakai