Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-47799

Опубликовано: 25 авг. 2025
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

Mahara before 22.10.4 and 23.x before 23.04.4 allows information disclosure if the experimental HTML bulk export is used via the administration interface or via the CLI, and the resulting export files are given to the account holders. They may contain images of other account holders because the cache is not cleared after the files of one account are exported.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:mahara:mahara:*:*:*:*:*:*:*:*
Версия до 22.10.4 (исключая)
cpe:2.3:a:mahara:mahara:*:*:*:*:*:*:*:*
Версия от 23.04.0 (включая) до 23.04.4 (исключая)

EPSS

Процентиль: 13%
0.00044
Низкий

7.5 High

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 7.5
debian
6 месяцев назад

Mahara before 22.10.4 and 23.x before 23.04.4 allows information discl ...

CVSS3: 7.5
github
6 месяцев назад

Mahara before 22.10.4 and 23.x before 23.04.4 allows information disclosure if the experimental HTML bulk export is used via the administration interface or via the CLI, and the resulting export files are given to the account holders. They may contain images of other account holders because the cache is not cleared after the files of one account are exported.

EPSS

Процентиль: 13%
0.00044
Низкий

7.5 High

CVSS3

Дефекты

CWE-200