CVE-2024-35203: Mahara
Medium severity, CVSS 6.1. EPSS: 0.2% chance of exploitation in the next 30 days.
Mahara before 22.10.6, 23.04.6, and 24.04.1 allows cross-site scripting (XSS) via a file, with JavaScript code as part of its name, that is uploaded via the Mahara filebrowser system.
Affected products
- Mahara Mahara: before 22.10.6 (fixed in 22.10.6); from 23.04.0, before 23.04.6 (fixed in 23.04.6); from 24.04.0, before 24.04.1 (fixed in 24.04.1)
Published 2025-08-26. Last modified 2026-06-17.