PT-2025-34608 · Mahara · Mahara

CVE-2023-47799

·

Published

2025-08-25

·

Updated

2025-08-29

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Mahara versions prior to 22.10.4 Mahara versions 23.x prior to 23.04.4
Description: Mahara is susceptible to information disclosure when the experimental HTML bulk export feature is utilized through the administration interface or command-line interface (CLI). The vulnerability arises from a failure to clear the cache after exporting files for one account, potentially including images belonging to other account holders in the exported files provided to account holders.
Recommendations: Update to Mahara version 22.10.4 or later. Update to Mahara version 23.04.4 or later.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-47799

Affected Products

Mahara