Mahara Information Disclosure Vulnerability in Group Administration Submissions Page

Vulnerability

A vulnerability exists in Mahara versions 24.04 prior to 24.04.1 and 23.04 prior to 23.04.6, allowing certain information to be disclosed to institution administrators. This occurs under specific conditions when accessing the 'Current submissions' page within the group administration section.

Impact

This vulnerability could lead to unauthorized information disclosure to institution administrators.

Remediation

Users can update to Mahara versions 24.04.1, 23.04.6, or 22.10.6. Instructions for downloading these versions are available on the Mahara Releases page.

Added: Aug 26, 2025, 3:47 PM
Updated: Aug 26, 2025, 3:47 PM

Vulnerability Rating

Custom Algorithm
spread
1.9
impact
2.5
exploitability
4.8
remediation
7.7
relevance
0.4
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.