Vulnerabilities
Vulnerable Software
Mahara:  >> Mahara  >> 21.04.2  Security Vulnerabilities
Mahara before 20.10.5, 21.04.4, 21.10.2, and 22.04.0 allows stored XSS when a particular Cascading Style Sheets (CSS) class for embedly is used, and JavaScript code is constructed to perform an action.
CVSS Score
5.4
EPSS Score
0.004
Published
2022-04-28
In Mahara before 20.10.5, 21.04.4, 21.10.2, and 22.04.0, a site using Isolated Institutions is vulnerable if more than ten groups are used. They are all shown from page 2 of the group results list (rather than only being shown for the institution that the viewer is a member of).
CVSS Score
7.5
EPSS Score
0.002
Published
2022-04-28
In Mahara 21.04 before 21.04.3 and 21.10 before 21.10.1, portfolios created in groups that have not been shared with non-group members and portfolios created on the site and institution levels can be viewed without requiring a login if the URL to these portfolios is known.
CVSS Score
5.3
EPSS Score
0.002
Published
2022-02-10
In Mahara 20.10 before 20.10.4, 21.04 before 21.04.3, and 21.10 before 21.10.1, the names of folders in the Files area can be seen by a person not owning the folders. (Only folder names are affected. Neither file names nor file contents are affected.)
CVSS Score
4.3
EPSS Score
0.002
Published
2022-02-09
In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, exporting collections via PDF export could lead to code execution via shell metacharacters in a collection name. Additional, in Mahara before 20.10.4, 21.04.3, and 21.10.1, exporting collections via PDF export could cause code execution
CVSS Score
7.3
EPSS Score
0.006
Published
2021-11-02


Contact Us

Shodan ® - All rights reserved