Vulnerability Description
Mahara before 22.10.4 and 23.x before 23.04.4 allows information disclosure if the experimental HTML bulk export is used via the administration interface or via the CLI, and the resulting export files are given to the account holders. They may contain images of other account holders because the cache is not cleared after the files of one account are exported.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mahara | Mahara | < 22.10.4 |
Related Weaknesses (CWE)
References
- https://git.mahara.org/catalyst-security/mahara-security/-/issues/2Broken Link
- https://mahara.org/interaction/forum/topic.php?id=9353Vendor Advisory
FAQ
What is CVE-2023-47799?
CVE-2023-47799 is a vulnerability with a CVSS score of 7.5 (HIGH). Mahara before 22.10.4 and 23.x before 23.04.4 allows information disclosure if the experimental HTML bulk export is used via the administration interface or via the CLI, and the resulting export files...
How severe is CVE-2023-47799?
CVE-2023-47799 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-47799?
Check the references section above for vendor advisories and patch information. Affected products include: Mahara Mahara.