Vulnerabilities > Mahara > High

DATE CVE VULNERABILITY TITLE RISK
2022-11-06 CVE-2022-42707 Unspecified vulnerability in Mahara
In Mahara 21.04 before 21.04.7, 21.10 before 21.10.5, 22.04 before 22.04.3, and 22.10 before 22.10.0, embedded images are accessible without a sufficient permission check under certain conditions.
network
low complexity
mahara
7.5
2022-06-20 CVE-2022-33913 Missing Authorization vulnerability in Mahara
In Mahara 21.04 before 21.04.6, 21.10 before 21.10.4, and 22.04.2, files can sometimes be downloaded through thumb.php with no permission check.
network
low complexity
mahara CWE-862
7.5
2022-04-28 CVE-2022-28892 Cross-Site Request Forgery (CSRF) vulnerability in Mahara
Mahara before 20.10.5, 21.04.4, 21.10.2, and 22.04.0 is vulnerable to Cross Site Request Forgery (CSRF) because randomly generated tokens are too easily guessable.
network
low complexity
mahara CWE-352
8.8
2022-04-28 CVE-2022-29585 Incorrect Default Permissions vulnerability in Mahara
In Mahara before 20.10.5, 21.04.4, 21.10.2, and 22.04.0, a site using Isolated Institutions is vulnerable if more than ten groups are used.
network
low complexity
mahara CWE-276
7.5
2021-11-03 CVE-2021-40848 Improper Neutralization of Formula Elements in a CSV File vulnerability in Mahara
In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, exported CSV files could contain characters that a spreadsheet program could interpret as a command, leading to execution of a malicious string locally on a device, aka CSV injection.
local
low complexity
mahara CWE-1236
7.8
2021-11-02 CVE-2021-43266 OS Command Injection vulnerability in Mahara
In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, exporting collections via PDF export could lead to code execution via shell metacharacters in a collection name.
local
low complexity
mahara CWE-78
7.3
2018-06-01 CVE-2018-11196 Unrestricted Upload of File with Dangerous Type vulnerability in Mahara
Mahara 17.04 before 17.04.8 and 17.10 before 17.10.5 and 18.04 before 18.04.1 can be used as medium to transmit viruses by placing infected files into a Leap2A archive and uploading that to Mahara.
network
low complexity
mahara CWE-434
7.5
2017-11-03 CVE-2017-1000151 Information Exposure vulnerability in Mahara
Mahara 15.04 before 15.04.9 and 15.10 before 15.10.5 and 16.04 before 16.04.3 are vulnerable to passwords or other sensitive information being passed by unusual parameters to end up in an error log.
network
low complexity
mahara CWE-200
7.5
2017-11-03 CVE-2017-1000150 Session Fixation vulnerability in Mahara
Mahara 15.04 before 15.04.7 and 15.10 before 15.10.3 are vulnerable to prevent session IDs from being regenerated on login or logout.
network
low complexity
mahara CWE-384
8.8
2017-11-03 CVE-2017-1000148 Deserialization of Untrusted Data vulnerability in Mahara
Mahara 15.04 before 15.04.8 and 15.10 before 15.10.4 and 16.04 before 16.04.2 are vulnerable to PHP code execution as Mahara would pass portions of the XML through the PHP "unserialize()" function when importing a skin from an XML file.
network
low complexity
mahara CWE-502
8.8