ZeroHour

CVE-2022-33913

PoC
CVSS 3.1
7.5 high
EPSS
1%p63
Published
()
Modified
Description

In Mahara 21.04 before 21.04.6, 21.10 before 21.10.4, and 22.04.2, files can sometimes be downloaded through thumb.php with no permission check.

Vendors
mahara
Products
mahara
Weakness
CWE-862
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.