Supported versions of Mahara 24.04 before 24.04.1 and 23.04 before 23.04.6 are vulnerable to information being disclosed to an institution administrator under certain conditions via the 'Current submissions' page: Administration -> Groups -> Submissions.
Under certain conditions, the administrative page 'Administration -> Groups -> Submissions' (so-called 'Current submissions') presents information to the institution administrator that they should not have access to. This is a CWE-200 class vulnerability (information disclosure) resulting from improper access control to data when displaying group submissions. The vulnerability does not require authentication as an attacker from outside the system, however, exploiting it requires having the role of institution administrator within the application.
An attacker with institution administrator privileges can gain unauthorized access to sensitive data concerning user submissions, which may violate user privacy and compliance requirements (e.g., GDPR).
Mahara should be updated to version 24.04.1 or 23.04.6 (depending on the branch in use). Detailed information is available in the producer's references on the Mahara forum.
Mahara in versions 24.04 before 24.04.1 and 23.04 before 23.04.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NMahara
APPMahara23.04.0 – 23.04.6 (excl.)24.04.0 – 24.04.1 (excl.)
Related vulnerabilities
Niebezpieczna deserializacja danych wejściowych w Mahara — RCE przez import skórki
Mahara: RCE przez eksport PDF z Ghostscript bez flagi -dSAFER
Mahara — niewystarczające zarządzanie tokenami web services umożliwia przejęcie konta
Mahara — pominięcie weryfikacji statusu instytucji przy logowaniu (Auth Bypass)
Mahara — nieważny link resetowania hasła umożliwia przejęcie konta