Ad

CVE-2026-33402

LOW CVSS 4.0: 1.3 EPSS 0.03%
Updated Mar 31, 2026
Sakailms
Parameter Value
CVSS 1.3 (LOW)
Affected Versions 23.0 — 25.2
Fixed In 23.5
Type CWE-79 (Cross-Site Scripting (XSS))
Vendor Sakailms
Public PoC No

Sakai is a Collaboration and Learning Environment (CLE). In versions 23.0 through 23.4 and 25.0 through 25.1, group titles and description can contain cross-site scripting scripts. The patch is included in releases 25.2 and 23.5.

As a workaround, one can check the SAKAI_SITE_GROUP table for titles and descriptions that contain this info.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Attack Requirements
None
No additional conditions
Privileges Required
None
No privileges needed
User Interaction
Passive
Minimal interaction

Impact Assessment

Confidentiality
None
No data leak
Integrity
None
No data modification
Availability
None
No disruption

CVSS Vector v4.0

Vulnerable Products 2

Configuration From (including) Up to (excluding)
Sakailms Sakai
cpe:2.3:a:sakailms:sakai:*:*:*:*:*:*:*:*
23.0 23.5
Sakailms Sakai
cpe:2.3:a:sakailms:sakai:*:*:*:*:*:*:*:*
25.0 25.2

Related Vulnerabilities