An issue was discovered in Mahara 23.04.8 and 24.04.4. The use of a malicious export download URL can allow an attacker to download files that they do not have permission to download.
Metrics
Affected Vendors & Products
References
History
Wed, 27 Aug 2025 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-494 | |
Metrics |
cvssV3_1
|
Wed, 27 Aug 2025 11:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Mahara
Mahara mahara |
|
Vendors & Products |
Mahara
Mahara mahara |
Tue, 26 Aug 2025 20:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An issue was discovered in Mahara 23.04.8 and 24.04.4. The use of a malicious export download URL can allow an attacker to download files that they do not have permission to download. | |
References |
|

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-08-27T16:22:16.133Z
Reserved: 2024-09-20T00:00:00.000Z
Link: CVE-2024-47192

Updated: 2025-08-27T16:22:11.801Z

Status : Awaiting Analysis
Published: 2025-08-26T21:15:47.217
Modified: 2025-08-29T16:22:31.970
Link: CVE-2024-47192

No data.

Updated: 2025-08-27T11:21:31Z