Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g4q3-wpfp-jw92

Опубликовано: 24 апр. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 4.7

Описание

In Mahara before 24.04.10 and 25 before 25.04.1, an institution administrator or institution support administrator on a multi-tenanted site can masquerade as an institution member in an institution for which they are not an administrator, if they also have the 'Site staff' role.

In Mahara before 24.04.10 and 25 before 25.04.1, an institution administrator or institution support administrator on a multi-tenanted site can masquerade as an institution member in an institution for which they are not an administrator, if they also have the 'Site staff' role.

EPSS

Процентиль: 7%
0.00177
Низкий

4.7 Medium

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 4.7
ubuntu
4 месяца назад

In Mahara before 24.04.10 and 25 before 25.04.1, an institution administrator or institution support administrator on a multi-tenanted site can masquerade as an institution member in an institution for which they are not an administrator, if they also have the 'Site staff' role.

CVSS3: 4.7
nvd
4 месяца назад

In Mahara before 24.04.10 and 25 before 25.04.1, an institution administrator or institution support administrator on a multi-tenanted site can masquerade as an institution member in an institution for which they are not an administrator, if they also have the 'Site staff' role.

CVSS3: 4.7
debian
4 месяца назад

In Mahara before 24.04.10 and 25 before 25.04.1, an institution admini ...

EPSS

Процентиль: 7%
0.00177
Низкий

4.7 Medium

CVSS3

Дефекты

CWE-284