CVE-2024-39335

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
26/08/2025
Last modified:
05/09/2025

Description

Supported versions of Mahara 24.04 before 24.04.1 and 23.04 before 23.04.6 are vulnerable to information being disclosed to an institution administrator under certain conditions via the 'Current submissions' page: Administration -> Groups -> Submissions.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mahara:mahara:*:*:*:*:*:*:*:* 23.04.0 (including) 23.04.6 (excluding)
cpe:2.3:a:mahara:mahara:*:*:*:*:*:*:*:* 24.04.0 (including) 24.04.1 (excluding)