Impact
Mahara before versions 25.04.5 and 26.04.0 allows artefacts to become accessible to other users when the file path to an artefact in a page is manipulated. An attacker who can modify the path can load artefacts that should remain private, resulting in the disclosure of potentially sensitive data stored on the platform.
Affected Systems
Installations of the Mahara e‑portfolio platform with versions older than 25.04.5 in the 25.x branch and older than 26.04.0 in the 26.x branch are affected. These releases do not enforce proper access checks on artefact paths, enabling unintended access.
Risk and Exploitability
The CVSS score of 9.1 indicates a high severity vulnerability. The EPSS score of less than 1% signals a low probability of exploitation in the wild, yet the vulnerability remains publicly documented and not listed in the CISA KEV catalog. The exploit requires the ability to manipulate artefact path parameters; based on the description, it is inferred that the likely attack vector involves remotely crafted URLs or form inputs on a publicly reachable Mahara instance. Because the vulnerability is not listed in the CISA KEV catalog, formalized exploitation data is lacking, but the potential for data leakage remains significant for environments that allow unauthenticated or loosely authenticated access to artefacts.
OpenCVE Enrichment