Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3m9j-mhpf-84wj

Опубликовано: 25 авг. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

Mahara before 22.10.4 and 23.x before 23.04.4 allows information disclosure if the experimental HTML bulk export is used via the administration interface or via the CLI, and the resulting export files are given to the account holders. They may contain images of other account holders because the cache is not cleared after the files of one account are exported.

Mahara before 22.10.4 and 23.x before 23.04.4 allows information disclosure if the experimental HTML bulk export is used via the administration interface or via the CLI, and the resulting export files are given to the account holders. They may contain images of other account holders because the cache is not cleared after the files of one account are exported.

EPSS

Процентиль: 13%
0.00044
Низкий

7.5 High

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 7.5
nvd
6 месяцев назад

Mahara before 22.10.4 and 23.x before 23.04.4 allows information disclosure if the experimental HTML bulk export is used via the administration interface or via the CLI, and the resulting export files are given to the account holders. They may contain images of other account holders because the cache is not cleared after the files of one account are exported.

CVSS3: 7.5
debian
6 месяцев назад

Mahara before 22.10.4 and 23.x before 23.04.4 allows information discl ...

EPSS

Процентиль: 13%
0.00044
Низкий

7.5 High

CVSS3

Дефекты

CWE-200