CVE-2022-33913: High severity mahara vulnerability
Published Jun 20, 2022
·Updated
In Mahara 21.04 before 21.04.6, 21.10 before 21.10.4, and 22.04.2, files can sometimes be downloaded through thumb.php with no permission check.
Affected Software
3 affected components
Mahara Mahara>=21.04.0<21.04.6
Mahara Mahara>=21.10.0<21.10.4
Mahara Mahara=22.04.2
Event History
Jun 20, 2022
CVE Published
via MITRE·03:26 PM
Data Sourced
via MITRE·03:26 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2022-33913.
2
What is the severity of CVE-2022-33913?
The severity of CVE-2022-33913 is high with a severity value of 7.5.
3
How can files be downloaded through thumb.php in Mahara?
In Mahara 21.04 before 21.04.6, 21.10 before 21.10.4, and 22.04.2, files can sometimes be downloaded through thumb.php with no permission check.
4
Which versions of Mahara are affected by CVE-2022-33913?
CVE-2022-33913 affects Mahara versions 21.04 before 21.04.6, 21.10 before 21.10.4, and 22.04.2.
5
How can I fix CVE-2022-33913?
To fix CVE-2022-33913, you should upgrade to Mahara version 21.04.6, 21.10.4, or 22.04.2.