Vulnerabilities (CVE)

Filtered by vendor Sakailms
Filtered by product Sakai
Angry Yack Logo
Total 3 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-47876 1 Sakailms 1 Sakai 2025-10-30 N/A 8.8 HIGH
Sakai is a Collaboration and Learning Environment. Starting in version 23.0 and prior to version 23.2, kernel users created with type roleview can log in as a normal user. This can result in illegal access being granted to the system. Version 23.3 fixes this vulnerability.
CVE-2025-62710 1 Sakailms 1 Sakai 2025-10-30 N/A 5.9 MEDIUM
Sakai is a Collaboration and Learning Environment. Prior to versions 23.5 and 25.0, EncryptionUtilityServiceImpl initialized an AES256TextEncryptor password (serverSecretKey) using RandomStringUtils with the default java.util.Random. java.util.Random is a non‑cryptographic PRNG and can be predicted from limited state/seed information (e.g., start time window), substantially reducing the effective search space of the generated key. An attacker who can obtain ciphertexts (e.g., exported or at‑rest ...

Show More

CVE-2019-16148 1 Sakailms 1 Sakai 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Sakai through 12.6 allows XSS via a chat user name.