CVE-2022-28892: CSRF
Published Apr 28, 2022
·Updated
Mahara before 20.10.5, 21.04.4, 21.10.2, and 22.04.0 is vulnerable to Cross Site Request Forgery (CSRF) because randomly generated tokens are too easily guessable.
Affected Software
4 affected components
Mahara Mahara<20.10.5
Mahara Mahara>=21.04.0<21.04.4
Mahara Mahara>=21.10.0<21.10.2
Mahara Mahara=22.04.0-rc1
Remediation
Patch Available
Event History
Apr 28, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2022-28892.
2
What is the severity level of CVE-2022-28892?
The severity level of CVE-2022-28892 is high with a severity value of 8.8.
3
What is the affected software?
The affected software is Mahara versions before 20.10.5, 21.04.4, 21.10.2, and 22.04.0.
4
What is the vulnerability description for CVE-2022-28892?
CVE-2022-28892 is a Cross-Site Request Forgery (CSRF) vulnerability in Mahara where randomly generated tokens are too easily guessable.
5
How can I fix CVE-2022-28892?
To fix CVE-2022-28892, you should update to Mahara versions 20.10.5, 21.04.4, 21.10.2, or 22.04.0.