AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2024-39923

MEDIUM · CVSS 6.1 EPSS 0.25%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2025-08-25 · Last synced 2026-08-04

CyberRota Analysis

This is a medium severity vulnerability with a CVSS score of 6.1. See the original NVD description below for full technical details.

CVE
CVE-2024-39923
Severity
MEDIUM
CVSS
6.1
EPSS
0.25%

Original NVD Description

An issue was discovered in Mahara 24.04 before 24.04.2 and 23.04 before 23.04.7. The About, Contact, and Help footer links can be set up to be vulnerable to Cross Site Scripting (XSS) due to not sanitising the values. These links can only be set up by an admin but are clickable by any logged-in person.

Related CVEs

Other vulnerabilities affecting the same vendor(s)