Mahara before 22.10.4 and 23.x before 23.04.4 allows information disclosure if the experimental HTML bulk export is used via the administration interface or via the CLI, and the resulting export files are given to the account holders. They may contain images of other account holders because the cache is not cleared after the files of one account are exported.
Metrics
Affected Vendors & Products
References
History
Fri, 05 Sep 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:mahara:mahara:*:*:*:*:*:*:*:* |
Mon, 25 Aug 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mahara
Mahara mahara |
|
| Vendors & Products |
Mahara
Mahara mahara |
Mon, 25 Aug 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-200 | |
| Metrics |
cvssV3_1
|
Mon, 25 Aug 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Mahara before 22.10.4 and 23.x before 23.04.4 allows information disclosure if the experimental HTML bulk export is used via the administration interface or via the CLI, and the resulting export files are given to the account holders. They may contain images of other account holders because the cache is not cleared after the files of one account are exported. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2025-08-25T00:00:00.000Z
Updated: 2025-08-25T20:39:28.708Z
Reserved: 2023-11-10T00:00:00.000Z
Link: CVE-2023-47799
Updated: 2025-08-25T20:39:23.232Z
Status : Analyzed
Published: 2025-08-25T14:15:28.907
Modified: 2025-09-05T17:05:01.243
Link: CVE-2023-47799
No data.