CyberRota
Back to database

CVE-2025-61872

MEDIUM · CVSS 6.1 EPSS 0.03%

Source: NVD + CISA KEV + EPSS · Published: 2026-04-24 · Last synced: 2026-05-24

CyberRota Analysis

Detaylı analiz gerekiyor.

CVE
CVE-2025-61872
Severity
MEDIUM
CVSS
6.1
EPSS
0.03%

Original NVD Description

Mahara before 25.04.2 and 24.04.11 are vulnerable to displaying results that can trigger XSS via a malicious search query string. This occurs in the 'search site' feature when using the Elasticsearch7 search plugin. The Elasticsearch function does not properly sanitize input in the query parameter.