CVE-2024-35203: XSS
Published Aug 26, 2025
·Updated
Mahara before 22.10.6, 23.04.6, and 24.04.1 allows cross-site scripting (XSS) via a file, with JavaScript code as part of its name, that is uploaded via the Mahara filebrowser system.
Affected Software
4 affected components
Mahara Mahara<22.10.6, <23.04.6, <24.04.1
Mahara Mahara<22.10.6
Mahara Mahara>=23.04.0<23.04.6
Mahara Mahara>=24.04.0<24.04.1
Event History
Aug 26, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-35203?
CVE-2024-35203 has a medium severity level due to its potential to allow cross-site scripting (XSS) attacks.
2
How do I fix CVE-2024-35203?
To fix CVE-2024-35203, upgrade Mahara to versions 22.10.6, 23.04.6, or 24.04.1 or later.
3
What products are affected by CVE-2024-35203?
CVE-2024-35203 affects Mahara versions earlier than 22.10.6, 23.04.6, and 24.04.1.
4
What type of vulnerability is CVE-2024-35203?
CVE-2024-35203 is classified as a cross-site scripting (XSS) vulnerability.
5
Can CVE-2024-35203 lead to data theft?
Yes, CVE-2024-35203 can potentially lead to data theft by allowing malicious scripts to execute in the user's browser.