CVE-2025-61872 Details
Description
Mahara before 25.04.2 and 24.04.11 are vulnerable to displaying results that can trigger XSS via a malicious search query string. This occurs in the 'search site' feature when using the Elasticsearch7 search plugin. The Elasticsearch function does not properly sanitize input in the query parameter.
A cross-site scripting (XSS) vulnerability has been identified in Mahara versions prior to 25.04.2 and 24.04.11. This issue arises in the 'search site' feature when the Elasticsearch7 search plugin is active. The vulnerability allows for the execution of malicious code by injecting harmful search query strings, which the Elasticsearch function fails to properly sanitize.
Users are advised to update to Mahara version 25.04.2 or 24.04.11. Instructions for updating Mahara are available in the Mahara manual.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Apr 24, 2026CISA-ADP
Assessed Apr 24, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://mahara.org | [email protected] | Vendor |
| https://mahara.org/interaction/forum/topic.php?id=9851 | [email protected] | AdvisoryBundleRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| Mahara | < 25.04.2 (semver) < 24.04.11 (semver) |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 24, 2026 | CVE Modified | CISA-ADP |
| Apr 24, 2026 | New CVE Received | [email protected] |
Volerion