Vulnerability Details CVE-2022-33913
In Mahara 21.04 before 21.04.6, 21.10 before 21.10.4, and 22.04.2, files can sometimes be downloaded through thumb.php with no permission check.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 47.0%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 4.3
Products affected by CVE-2022-33913
-
cpe:2.3:a:mahara:mahara:21.04.0
-
cpe:2.3:a:mahara:mahara:21.04.1
-
cpe:2.3:a:mahara:mahara:21.04.2
-
cpe:2.3:a:mahara:mahara:21.04.3
-
cpe:2.3:a:mahara:mahara:21.04.4
-
cpe:2.3:a:mahara:mahara:21.10.0
-
cpe:2.3:a:mahara:mahara:21.10.1
-
cpe:2.3:a:mahara:mahara:21.10.2
-
cpe:2.3:a:mahara:mahara:22.04.2