Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
mahara mahara 21.10.0 vulnerabilities and exploits
(subscribe to this query)
4.3
CVSSv3
CVE-2022-24694
In Mahara 20.10 prior to 20.10.4, 21.04 prior to 21.04.3, and 21.10 prior to 21.10.1, the names of folders in the Files area can be seen by a person not owning the folders. (Only folder names are affected. Neither file names nor file contents are affected.)
Mahara Mahara
Mahara Mahara 21.10.0
5.3
CVSSv3
CVE-2022-24111
In Mahara 21.04 prior to 21.04.3 and 21.10 prior to 21.10.1, portfolios created in groups that have not been shared with non-group members and portfolios created on the site and institution levels can be viewed without requiring a login if the URL to these portfolios is known.
Mahara Mahara
Mahara Mahara 21.10.0
7.8
CVSSv3
CVE-2021-40848
In Mahara prior to 20.04.5, 20.10.3, 21.04.2, and 21.10.0, exported CSV files could contain characters that a spreadsheet program could interpret as a command, leading to execution of a malicious string locally on a device, aka CSV injection.
Mahara Mahara
Mahara Mahara 21.10.0
9.8
CVSSv3
CVE-2021-40849
In Mahara prior to 20.04.5, 20.10.3, 21.04.2, and 21.10.0, the account associated with a web services token is vulnerable to being exploited and logged into, resulting in information disclosure (at a minimum) and often escalation of privileges.
Mahara Mahara
Mahara Mahara 21.10.0
5.4
CVSSv3
CVE-2021-43265
In Mahara prior to 20.04.5, 20.10.3, 21.04.2, and 21.10.0, certain tag syntax could be used for XSS, such as via a SCRIPT element.
Mahara Mahara
3.3
CVSSv3
CVE-2021-43264
In Mahara prior to 20.04.5, 20.10.3, 21.04.2, and 21.10.0, adjusting the path component for the page help file allows malicious users to bypass the intended access control for HTML files via directory traversal. It replaces the - character with the / character.
Mahara Mahara
7.3
CVSSv3
CVE-2021-43266
In Mahara prior to 20.04.5, 20.10.3, 21.04.2, and 21.10.0, exporting collections via PDF export could lead to code execution via shell metacharacters in a collection name. Additional, in Mahara prior to 20.10.4, 21.04.3, and 21.10.1, exporting collections via PDF export could cau...
Mahara Mahara
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-33572
CVE-2024-24919
CVE-2024-0230
CVE-2024-32714
HTML injection
local file inclusion
CVE-2024-31098
CVE-2024-31244
privilege
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started