Home

Description

An issue was discovered in Mahara 23.04.8 and 24.04.4. The use of a malicious export download URL can allow an attacker to download files that they do not have permission to download.

PUBLISHED Reserved 2024-09-20 | Published 2025-08-26 | Updated 2025-08-27 | Assigner mitre

References

mahara.org/interaction/forum/view.php?id=43

mahara.org/interaction/forum/topic.php?id=9594

cve.org (CVE-2024-47192)

nvd.nist.gov (CVE-2024-47192)

Download JSON