Mahara

Mahara

108 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.2%
  • Veröffentlicht 06.11.2022 17:15:10
  • Zuletzt bearbeitet 02.05.2025 19:15:54

In Mahara 21.04 before 21.04.7, 21.10 before 21.10.5, 22.04 before 22.04.3, and 22.10 before 22.10.0, embedded images are accessible without a sufficient permission check under certain conditions.

  • EPSS 0.29%
  • Veröffentlicht 06.11.2022 17:15:10
  • Zuletzt bearbeitet 02.05.2025 19:15:54

Mahara 21.04 before 21.04.7, 21.10 before 21.10.5, 22.04 before 22.04.3, and 22.10 before 22.10.0 potentially allow a PDF export to trigger a remote shell if the site is running on Ubuntu and the flag -dSAFER is not set with Ghostscript.

Exploit
  • EPSS 0.24%
  • Veröffentlicht 20.06.2022 16:15:08
  • Zuletzt bearbeitet 21.11.2024 07:08:35

In Mahara 21.04 before 21.04.6, 21.10 before 21.10.4, and 22.04.2, files can sometimes be downloaded through thumb.php with no permission check.

  • EPSS 0.1%
  • Veröffentlicht 28.04.2022 16:15:08
  • Zuletzt bearbeitet 21.11.2024 06:58:08

Mahara before 20.10.5, 21.04.4, 21.10.2, and 22.04.0 is vulnerable to Cross Site Request Forgery (CSRF) because randomly generated tokens are too easily guessable.

  • EPSS 0.44%
  • Veröffentlicht 28.04.2022 16:15:08
  • Zuletzt bearbeitet 21.11.2024 06:59:21

Mahara before 20.10.5, 21.04.4, 21.10.2, and 22.04.0 allows stored XSS when a particular Cascading Style Sheets (CSS) class for embedly is used, and JavaScript code is constructed to perform an action.

  • EPSS 0.24%
  • Veröffentlicht 28.04.2022 16:15:08
  • Zuletzt bearbeitet 21.11.2024 06:59:21

In Mahara before 20.10.5, 21.04.4, 21.10.2, and 22.04.0, a site using Isolated Institutions is vulnerable if more than ten groups are used. They are all shown from page 2 of the group results list (rather than only being shown for the institution tha...

  • EPSS 0.2%
  • Veröffentlicht 10.02.2022 16:15:07
  • Zuletzt bearbeitet 21.11.2024 06:49:49

In Mahara 21.04 before 21.04.3 and 21.10 before 21.10.1, portfolios created in groups that have not been shared with non-group members and portfolios created on the site and institution levels can be viewed without requiring a login if the URL to the...

Exploit
  • EPSS 0.19%
  • Veröffentlicht 09.02.2022 05:15:09
  • Zuletzt bearbeitet 21.11.2024 06:50:53

In Mahara 20.10 before 20.10.4, 21.04 before 21.04.3, and 21.10 before 21.10.1, the names of folders in the Files area can be seen by a person not owning the folders. (Only folder names are affected. Neither file names nor file contents are affected....

  • EPSS 0.75%
  • Veröffentlicht 03.11.2021 11:15:08
  • Zuletzt bearbeitet 21.11.2024 06:24:55

In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, exported CSV files could contain characters that a spreadsheet program could interpret as a command, leading to execution of a malicious string locally on a device, aka CSV injection.

  • EPSS 0.43%
  • Veröffentlicht 03.11.2021 11:15:08
  • Zuletzt bearbeitet 21.11.2024 06:24:55

In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, the account associated with a web services token is vulnerable to being exploited and logged into, resulting in information disclosure (at a minimum) and often escalation of privileges.