CVE-2021-43265: XSS
Published Nov 2, 2021
·Updated
In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, certain tag syntax could be used for XSS, such as via a SCRIPT element.
Affected Software
3 affected components
Mahara Mahara>=20.04.0<20.04.5
Mahara Mahara>=20.10.0<20.10.3
Mahara Mahara>=21.04.0<21.04.2
Event History
Nov 2, 2021
CVE Published
via MITRE·09:55 PM
Data Sourced
via MITRE·09:55 PM
Description
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this Mahara vulnerability?
The vulnerability ID for this Mahara vulnerability is CVE-2021-43265.
2
What is the severity of CVE-2021-43265?
The severity of CVE-2021-43265 is medium (5.4).
3
What is the affected software for CVE-2021-43265?
The affected software for CVE-2021-43265 is Mahara versions 20.04.0 to 20.04.5, 20.10.0 to 20.10.3, and 21.04.0 to 21.04.2.
4
What is the description of CVE-2021-43265?
CVE-2021-43265 is a vulnerability in Mahara before versions 20.04.5, 20.10.3, 21.04.2, and 21.10.0 that allows for XSS attacks using certain tag syntax, such as via a SCRIPT element.
5
How can I fix CVE-2021-43265?
To fix CVE-2021-43265, it is recommended to update to Mahara versions 20.04.5, 20.10.3, 21.04.2, or 21.10.0.