CVE-2022-24694: Medium severity mahara vulnerability
In Mahara 20.10 before 20.10.4, 21.04 before 21.04.3, and 21.10 before 21.10.1, the names of folders in the Files area can be seen by a person not owning the folders. (Only folder names are affected. Neither file names nor file contents are affected.)
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-24694?
CVE-2022-24694 is a vulnerability in Mahara versions before 20.10.4, 21.04 before 21.04.3, and 21.10 before 21.10.1 that allows unauthorized users to see the names of folders in the Files area.
How does CVE-2022-24694 affect Mahara?
CVE-2022-24694 allows users who do not own the folders to see the names of folders in the Files area, but it does not affect file names or file contents.
What is the severity of CVE-2022-24694?
CVE-2022-24694 has a severity rating of 4.3, which is considered medium.
How can I fix CVE-2022-24694?
To fix CVE-2022-24694, you should update your Mahara installation to version 20.10.4, 21.04.3, or 21.10.1 depending on your current version.
Where can I find more information about CVE-2022-24694?
You can find more information about CVE-2022-24694 on the Mahara bug tracker and the Mahara community forum.