CVE-2021-40848: High severity mahara vulnerability
Published Nov 3, 2021
·Updated
In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, exported CSV files could contain characters that a spreadsheet program could interpret as a command, leading to execution of a malicious string locally on a device, aka CSV injection.
Affected Software
5 affected components
Mahara Mahara<20.04.5
Mahara Mahara>=20.10.0<20.10.3
Mahara Mahara>=21.04.0<21.04.2
Mahara Mahara=21.10.0-rc1
Mahara Mahara=21.10.0-rc2
Event History
Nov 3, 2021
CVE Published
via MITRE·10:11 AM
Data Sourced
via MITRE·10:11 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2021-40848.
2
What is the severity of CVE-2021-40848?
The severity of CVE-2021-40848 is high.
3
Which versions of Mahara are affected by CVE-2021-40848?
Mahara versions before 20.04.5, 20.10.3, 21.04.2, and 21.10.0 are affected by CVE-2021-40848.
4
What is the risk of CVE-2021-40848?
CVE-2021-40848 could allow malicious execution of code on a device.
5
How can I fix CVE-2021-40848?
To fix CVE-2021-40848, update your Mahara installation to version 20.04.5, 20.10.3, 21.04.2, or 21.10.0.