Mahara
cpe:2.3:a:mahara:mahara:*:*:*:*:*:*:*
- < 23.04.9
- < 24.04.5
A vulnerability allowing escalation of privileges has been identified in Mahara versions 23.04.8 and 24.04.4. This issue arises when users log into Mahara using Learning Tools Interoperability (LTI), particularly affecting sites with suspended or expired accounts.
Exploitation of this vulnerability could lead to unauthorized access to elevated privileges, allowing users to perform actions or access resources that are normally restricted.
Users can update to Mahara 24.04.6, which is available via the Mahara Git repository or as a downloadable package. Instructions for updating Mahara are available in the Mahara manual.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.