PT-2025-34812 · Mahara · Mahara

Published

2025-08-26

·

Updated

2025-08-27

·

CVE-2024-35203

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Mahara versions prior to 22.10.6 Mahara versions prior to 23.04.6 Mahara versions prior to 24.04.1
Description: The application allows cross-site scripting (XSS) via a file uploaded through the Mahara filebrowser system. The vulnerability occurs when a file with JavaScript code in its name is uploaded.
Recommendations: Update Mahara to version 22.10.6 or later. Update Mahara to version 23.04.6 or later. Update Mahara to version 24.04.1 or later.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-35203

Affected Products

Mahara