Vulnerability Description
In Mahara 20.10 before 20.10.4, 21.04 before 21.04.3, and 21.10 before 21.10.1, the names of folders in the Files area can be seen by a person not owning the folders. (Only folder names are affected. Neither file names nor file contents are affected.)
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mahara | Mahara | >= 20.10.0, < 20.10.4 |
Related Weaknesses (CWE)
References
- https://bugs.launchpad.net/mahara/+bug/1952808ExploitIssue TrackingThird Party Advisory
- https://mahara.org/interaction/forum/topic.php?id=8994Vendor Advisory
- https://bugs.launchpad.net/mahara/+bug/1952808ExploitIssue TrackingThird Party Advisory
- https://mahara.org/interaction/forum/topic.php?id=8994Vendor Advisory
FAQ
What is CVE-2022-24694?
CVE-2022-24694 is a vulnerability with a CVSS score of 4.3 (MEDIUM). In Mahara 20.10 before 20.10.4, 21.04 before 21.04.3, and 21.10 before 21.10.1, the names of folders in the Files area can be seen by a person not owning the folders. (Only folder names are affected. ...
How severe is CVE-2022-24694?
CVE-2022-24694 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-24694?
Check the references section above for vendor advisories and patch information. Affected products include: Mahara Mahara.