Mahara
cpe:2.3:a:mahara:mahara:*:*:*:*:*:*:*
- 23.04.8
- 24.04.4
A directory traversal vulnerability has been identified in Mahara versions 23.04.8 and 24.04.4. This vulnerability allows an attacker to exploit a malicious export download URL to access and download files without proper authorization.
Exploitation of this vulnerability could lead to unauthorized information disclosure by allowing attackers to download restricted files.
Users can update to Mahara versions 23.04.9 or 24.04.5, both of which include the necessary fix. Instructions for updating Mahara are available on the Mahara wiki.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.