PT-2025-34496 · Mahara · Mahara

Published

2025-08-22

·

Updated

2025-08-23

·

CVE-2022-45133

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Mahara versions 21.10 through 21.10.6 Mahara versions 22.04 through 22.04.4 Mahara versions 22.10 through 22.10.1
Description: The application allows unsafe font uploads for skins. A specifically crafted XML file may enable unauthorized access to secure files or potentially lead to code execution.
Recommendations: Update Mahara to version 21.10.6 or later. Update Mahara to version 22.04.4 or later. Update Mahara to version 22.10.1 or later.

Fix

Weakness Enumeration

Related Identifiers

CVE-2022-45133

Affected Products

Mahara