CRITICAL🇵🇱 Wersja polska

CVE-2024-39335

CVSS 9.1v3.1pub. 2025-08-26upd. 2025-09-05

Supported versions of Mahara 24.04 before 24.04.1 and 23.04 before 23.04.6 are vulnerable to information being disclosed to an institution administrator under certain conditions via the 'Current submissions' page: Administration -> Groups -> Submissions.

🤖 AI Analysis
How it works

Under certain conditions, the administrative page 'Administration -> Groups -> Submissions' (so-called 'Current submissions') presents information to the institution administrator that they should not have access to. This is a CWE-200 class vulnerability (information disclosure) resulting from improper access control to data when displaying group submissions. The vulnerability does not require authentication as an attacker from outside the system, however, exploiting it requires having the role of institution administrator within the application.

Impact

An attacker with institution administrator privileges can gain unauthorized access to sensitive data concerning user submissions, which may violate user privacy and compliance requirements (e.g., GDPR).

Mitigation & patch

Mahara should be updated to version 24.04.1 or 23.04.6 (depending on the branch in use). Detailed information is available in the producer's references on the Mahara forum.

Who is affected

Mahara in versions 24.04 before 24.04.1 and 23.04 before 23.04.6

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
  • Mahara

    APP
    Mahara
    23.04.0 – 23.04.6 (excl.)24.04.0 – 24.04.1 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2022-45134CRITICAL9.8PL ✓same product

Niebezpieczna deserializacja danych wejściowych w Mahara — RCE przez import skórki

CVE-2022-44544CRITICAL9.8PL ✓same product

Mahara: RCE przez eksport PDF z Ghostscript bez flagi -dSAFER

CVE-2021-40849CRITICAL9.8PL ✓same product

Mahara — niewystarczające zarządzanie tokenami web services umożliwia przejęcie konta

CVE-2017-1000154CRITICAL9.8PL ✓same product

Mahara — pominięcie weryfikacji statusu instytucji przy logowaniu (Auth Bypass)

CVE-2017-1000153CRITICAL9.8PL ✓same product

Mahara — nieważny link resetowania hasła umożliwia przejęcie konta