CVE-2024-45753: XSS
Published Aug 26, 2025
·Updated
In Mahara 23.04.8 and 24.04.4, the external RSS feed block can cause XSS if the external feed XML has a malicious value for the link attribute.
Affected Software
3 affected components
Mahara Mahara>=23.04.8<=24.04.4
Mahara Mahara<23.04.9
Mahara Mahara>=24.04.0<24.04.5
Event History
Aug 26, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-45753?
CVE-2024-45753 is classified as a moderate severity vulnerability due to the potential for XSS attacks.
2
How do I fix CVE-2024-45753?
To mitigate CVE-2024-45753, ensure you strip or validate external RSS feed links before rendering them in your application.
3
What versions of Mahara are affected by CVE-2024-45753?
CVE-2024-45753 affects Mahara versions 23.04.8 and 24.04.4.
4
What type of vulnerability is CVE-2024-45753?
CVE-2024-45753 is an XSS (Cross-Site Scripting) vulnerability caused by unvalidated external RSS feed links.
5
Can I exploit CVE-2024-45753 in any Mahara installation?
Exploitation of CVE-2024-45753 requires a Mahara installation that uses the external RSS feed block with a malicious XML feed.