Vulnerabilities
Vulnerable Software
Mahara:  >> Mahara  >> 18.10.0  Security Vulnerabilities
In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, the account associated with a web services token is vulnerable to being exploited and logged into, resulting in information disclosure (at a minimum) and often escalation of privileges.
CVSS Score
9.8
EPSS Score
0.004
Published
2021-11-03
In Mahara 18.10 before 18.10.5, 19.04 before 19.04.4, and 19.10 before 19.10.2, file metadata information is disclosed to group members in the Elasticsearch result list despite them not having access to that artefact anymore.
CVSS Score
4.3
EPSS Score
0.002
Published
2020-03-09
In Mahara 18.10 before 18.10.5, 19.04 before 19.04.4, and 19.10 before 19.10.2, certain personal information is discoverable inspecting network responses on the 'Edit access' screen when sharing portfolios.
CVSS Score
6.5
EPSS Score
0.003
Published
2020-03-09
An issue was discovered in Mahara 17.10 before 17.10.8, 18.04 before 18.04.4, and 18.10 before 18.10.1. A site administrator can suspend the system user (root), causing all users to be locked out from the system.
CVSS Score
4.9
EPSS Score
0.004
Published
2019-05-07
An issue was discovered in Mahara 17.10 before 17.10.8, 18.04 before 18.04.4, and 18.10 before 18.10.1. The collection title is vulnerable to Cross Site Scripting (XSS) due to not escaping it when viewing the collection's SmartEvidence overview page (if that feature is turned on). This can be exploited by any logged-in user.
CVSS Score
5.4
EPSS Score
0.003
Published
2019-05-07


Contact Us

Shodan ® - All rights reserved