Sakai is a Collaboration and Learning Environment (CLE). In versions 23.0 through 23.4 and 25.0 through 25.1, group titles and description can contain cross-site scripting scripts. The patch is included in releases 25.2 and 23.5. As a workaround, one can check the SAKAI_SITE_GROUP table for titles and descriptions that contain this info.
Metrics
Affected Vendors & Products
References
History
Thu, 26 Mar 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Sakai is a Collaboration and Learning Environment (CLE). In versions 23.0 through 23.4 and 25.0 through 25.1, group titles and description can contain cross-site scripting scripts. The patch is included in releases 25.2 and 23.5. As a workaround, one can check the SAKAI_SITE_GROUP table for titles and descriptions that contain this info. | |
| Title | SAK-52311: Sakai site-manage group titles can contain XSS content | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-26T16:45:59.734Z
Reserved: 2026-03-19T17:02:34.170Z
Link: CVE-2026-33402
No data.
Status : Received
Published: 2026-03-26T17:16:38.287
Modified: 2026-03-26T17:16:38.287
Link: CVE-2026-33402
No data.
OpenCVE Enrichment
No data.