Impact
A crafted call within Mahara’s Text block or section functionality can trigger the recall of backed‑up content from a different Text section. This behaviour allows an attacker to read data that should be otherwise inaccessible, potentially exposing confidential or sensitive information stored in the system. The vulnerability represents an information disclosure flaw rather than a code execution or denial‑of‑service issue.
Affected Systems
Mahara versions prior to 25.04.5 and 26.04.0 are affected. The exploit targets the platform’s built‑in Text block/section feature and any instance that runs these unpatched releases.
Risk and Exploitability
No EPSS score is available and the vulnerability has not been listed in CISA’s KEV catalog, indicating no known widespread exploitation. The attack vector appears to be via a crafted request to the Text block interface, which may be accessible to authenticated users with sufficient permissions. Depending on user rights, the risk level varies, but the lack of exploitation data suggests a moderate risk unless the affected platform is publicly reachable and users can exercise the vulnerable functionality.
OpenCVE Enrichment