Impact
Mahara installations before version 25.04.5 in the 25.x line or before 26.04.0 in the 26.x line have a flaw that allows an attacker who can interact with the Learning Tools Interoperability (LTI) interfaces to gain unauthorized access to internal account information. The weakness arises when LTI 1.1 or LTI 1.3 Advantage is used under specific circumstances, enabling the attacker to read or misuse account credentials that would normally be protected. This erodes user confidentiality and can lead to further compromise of the Mahara platform.
Affected Systems
The affected product is the Mahara e‑learning platform. Only versions prior to 25.04.5 in the 25.x release line and prior to 26.04.0 in the 26.x release line are impacted. No additional vendor details are provided, so administrators must confirm the exact version of their Mahara deployment to determine whether they are vulnerable.
Risk and Exploitability
Based on the description, it is inferred that the attacker can trigger the vulnerability by sending an LTI request from an external network to the site, i.e., the attack vector is through the public network interface. The attacker can exploit the flaw remotely by any user who can send an LTI request to the affected site. The CVSS score of 9.8 indicates critical severity, while the EPSS score of less than 1% suggests a low probability of exploitation at present. Nevertheless, the vulnerability poses a significant threat because it allows unauthorized account access that could compromise user confidentiality and platform integrity. The issue is not listed in the CISA KEV catalog but should still be treated as a substantial risk until the platform is updated.
OpenCVE Enrichment