CVE-2022-33913

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
20/06/2022
Last modified:
08/08/2023

Description

In Mahara 21.04 before 21.04.6, 21.10 before 21.10.4, and 22.04.2, files can sometimes be downloaded through thumb.php with no permission check.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mahara:mahara:*:*:*:*:*:*:*:* 21.04.0 (including) 21.04.6 (excluding)
cpe:2.3:a:mahara:mahara:*:*:*:*:*:*:*:* 21.10.0 (including) 21.10.4 (excluding)
cpe:2.3:a:mahara:mahara:22.04.2:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools