CVE-2021-40849: Critical severity mahara vulnerability
In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, the account associated with a web services token is vulnerable to being exploited and logged into, resulting in information disclosure (at a minimum) and often escalation of privileges.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-40849?
CVE-2021-40849 is a vulnerability in Mahara versions before 20.04.5, 20.10.3, 21.04.2, and 21.10.0 that allows the account associated with a web services token to be exploited, leading to information disclosure and potential privilege escalation.
How severe is CVE-2021-40849?
CVE-2021-40849 has a severity rating of 9.8 (critical).
How can I fix CVE-2021-40849?
To fix CVE-2021-40849, it is recommended to update to Mahara versions 20.04.5, 20.10.3, 21.04.2, or 21.10.0 or later.
What is the Common Weakness Enumeration (CWE) for CVE-2021-40849?
The Common Weakness Enumeration (CWE) for CVE-2021-40849 is CWE-613.
Where can I find more information about CVE-2021-40849?
More information about CVE-2021-40849 can be found at the following references: [1](https://bugs.launchpad.net/mahara/+bug/1930469) and [2](https://mahara.org/interaction/forum/topic.php?id=8949).