CVE-2024-47192
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
26/08/2025
Last modified:
05/09/2025
Description
An issue was discovered in Mahara 23.04.8 and 24.04.4. The use of a malicious export download URL can allow an attacker to download files that they do not have permission to download.
Impact
Base Score 3.x
5.30
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:mahara:mahara:*:*:*:*:*:*:*:* | 23.04.9 (excluding) | |
| cpe:2.3:a:mahara:mahara:*:*:*:*:*:*:*:* | 24.04.0 (including) | 24.04.5 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



