Vulnerabilities
Vulnerable Software
Mahara:  >> Mahara  >> 1.0.1  Security Vulnerabilities
Mahara before 22.10.6, 23.04.6, and 24.04.1 allows cross-site scripting (XSS) via a file, with JavaScript code as part of its name, that is uploaded via the Mahara filebrowser system.
CVSS Score
6.1
EPSS Score
0.0
Published
2025-08-26
An issue was discovered in Mahara 23.04.8 and 24.04.4. The use of a malicious export download URL can allow an attacker to download files that they do not have permission to download.
CVSS Score
5.3
EPSS Score
0.0
Published
2025-08-26
Mahara before 24.04.9 exposes database connection information if the database becomes unreachable, e.g., due to the database server being temporarily down or too busy.
CVSS Score
7.5
EPSS Score
0.0
Published
2025-08-26
An issue was discovered in Mahara 23.04.8 and 24.04.4. Attackers may utilize escalation of privileges in certain cases when logging into Mahara with Learning Tools Interoperability (LTI).
CVSS Score
8.8
EPSS Score
0.001
Published
2025-08-26
In Mahara 23.04.8 and 24.04.4, the external RSS feed block can cause XSS if the external feed XML has a malicious value for the link attribute.
CVSS Score
6.1
EPSS Score
0.0
Published
2025-08-26
Mahara before 22.10.4 and 23.x before 23.04.4 allows information disclosure if the experimental HTML bulk export is used via the administration interface or via the CLI, and the resulting export files are given to the account holders. They may contain images of other account holders because the cache is not cleared after the files of one account are exported.
CVSS Score
7.5
EPSS Score
0.0
Published
2025-08-25
Mahara before 20.10.5, 21.04.4, 21.10.2, and 22.04.0 is vulnerable to Cross Site Request Forgery (CSRF) because randomly generated tokens are too easily guessable.
CVSS Score
8.8
EPSS Score
0.001
Published
2022-04-28
Mahara before 20.10.5, 21.04.4, 21.10.2, and 22.04.0 allows stored XSS when a particular Cascading Style Sheets (CSS) class for embedly is used, and JavaScript code is constructed to perform an action.
CVSS Score
5.4
EPSS Score
0.004
Published
2022-04-28
In Mahara before 20.10.5, 21.04.4, 21.10.2, and 22.04.0, a site using Isolated Institutions is vulnerable if more than ten groups are used. They are all shown from page 2 of the group results list (rather than only being shown for the institution that the viewer is a member of).
CVSS Score
7.5
EPSS Score
0.002
Published
2022-04-28
In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, exported CSV files could contain characters that a spreadsheet program could interpret as a command, leading to execution of a malicious string locally on a device, aka CSV injection.
CVSS Score
7.8
EPSS Score
0.007
Published
2021-11-03


Contact Us

Shodan ® - All rights reserved