CVE-2022-29584: XSS
Published Apr 28, 2022
·Updated
Mahara before 20.10.5, 21.04.4, 21.10.2, and 22.04.0 allows stored XSS when a particular Cascading Style Sheets (CSS) class for embedly is used, and JavaScript code is constructed to perform an action.
Affected Software
4 affected components
Mahara Mahara<20.10.5
Mahara Mahara>=21.04.0<21.04.4
Mahara Mahara>=21.10.0<21.10.2
Mahara Mahara=22.04.0-rc1
Event History
Apr 28, 2022
CVE Published
via MITRE·03:26 PM
Data Sourced
via MITRE·03:26 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-29584?
The severity of CVE-2022-29584 is medium with a CVSS score of 5.4.
2
How does CVE-2022-29584 affect Mahara?
CVE-2022-29584 affects Mahara versions before 20.10.5, 21.04.4, 21.10.2, and 22.04.0.
3
What is the vulnerability type of CVE-2022-29584?
CVE-2022-29584 is a stored cross-site scripting (XSS) vulnerability.
4
How can an attacker exploit CVE-2022-29584?
By using a particular Cascading Style Sheets (CSS) class for embedly and constructing JavaScript code, an attacker can perform a stored XSS attack.
5
Are there any known fixes for CVE-2022-29584?
Yes, the fix for CVE-2022-29584 is to upgrade to Mahara versions 20.10.5, 21.04.4, 21.10.2, or 22.04.0.