Mahara

Mahara

113 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.15%
  • Veröffentlicht 17.08.2026 00:00:00
  • Zuletzt bearbeitet 31.08.2026 20:12:02

Mahara before 25.04.5 and 26.04.0 is vulnerable to unauthorized access to internal accounts via Learning Tools Interoperability (LTI) under certain circumstances. This applies to LTI 1.1 and LTI 1.3 Advantage.

  • EPSS 0.15%
  • Veröffentlicht 17.08.2026 00:00:00
  • Zuletzt bearbeitet 31.08.2026 20:12:02

Mahara before 25.04.5 and 26.04.0 is vulnerable in the Text block/section functionality when a call is crafted in a certain way that allows it to recall the backed-up content from another Text section.

  • EPSS 0.15%
  • Veröffentlicht 17.08.2026 00:00:00
  • Zuletzt bearbeitet 31.08.2026 20:12:02

Mahara before 25.04.5 and 26.04.0 is vulnerable to artefacts being accessible to others under certain circumstances when the file path to an artefact in a page is manipulated.

  • EPSS 0.19%
  • Veröffentlicht 24.04.2026 00:00:00
  • Zuletzt bearbeitet 24.04.2026 17:54:36

Mahara before 25.04.2 and 24.04.11 are vulnerable to displaying results that can trigger XSS via a malicious search query string. This occurs in the 'search site' feature when using the Elasticsearch7 search plugin. The Elasticsearch function does no...

  • EPSS 0.18%
  • Veröffentlicht 24.04.2026 00:00:00
  • Zuletzt bearbeitet 24.04.2026 17:54:36

In Mahara before 24.04.10 and 25 before 25.04.1, an institution administrator or institution support administrator on a multi-tenanted site can masquerade as an institution member in an institution for which they are not an administrator, if they als...

  • EPSS 0.32%
  • Veröffentlicht 26.08.2025 14:15:37
  • Zuletzt bearbeitet 05.09.2025 17:02:09

Mahara before 24.04.9 exposes database connection information if the database becomes unreachable, e.g., due to the database server being temporarily down or too busy.

  • EPSS 0.31%
  • Veröffentlicht 26.08.2025 14:15:35
  • Zuletzt bearbeitet 22.09.2025 16:15:38

An issue was discovered in Mahara 23.04.8 and 24.04.4. Attackers may utilize escalation of privileges in certain cases when logging into Mahara with Learning Tools Interoperability (LTI).

  • EPSS 0.2%
  • Veröffentlicht 26.08.2025 14:15:34
  • Zuletzt bearbeitet 05.09.2025 17:04:26

In Mahara 23.04.8 and 24.04.4, the external RSS feed block can cause XSS if the external feed XML has a malicious value for the link attribute.

  • EPSS 0.32%
  • Veröffentlicht 26.08.2025 00:00:00
  • Zuletzt bearbeitet 05.09.2025 17:00:50

Supported versions of Mahara 24.04 before 24.04.1 and 23.04 before 23.04.6 are vulnerable to information being disclosed to an institution administrator under certain conditions via the 'Current submissions' page: Administration -> Groups -> Submissi...

  • EPSS 0.2%
  • Veröffentlicht 26.08.2025 00:00:00
  • Zuletzt bearbeitet 05.09.2025 16:59:11

Mahara before 22.10.6, 23.04.6, and 24.04.1 allows cross-site scripting (XSS) via a file, with JavaScript code as part of its name, that is uploaded via the Mahara filebrowser system.