EIP-2026-103295
PRE-CVEMahara 19.10.2 CMS - Persistent Cross-Site Scripting
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-103295. PoCs published by Vulnerability-Lab.
AI-analyzed exploit summary This exploit demonstrates a persistent XSS vulnerability in Mahara CMS v19.10.2, where malicious script code can be injected via the 'nombre' and 'descripción' parameters in the 'Ficheros' module. The payload is executed when higher-privileged users interact with the injected content.
Description
Mahara 19.10.2 CMS - Persistent Cross-Site Scripting
Exploits (1)
This exploit demonstrates a persistent XSS vulnerability in Mahara CMS v19.10.2, where malicious script code can be injected via the 'nombre' and 'descripción' parameters in the 'Ficheros' module. The payload is executed when higher-privileged users interact with the injected content.