CVE-2022-45133: Medium severity Mahara Mahara vulnerability
Mahara 21.10 before 21.10.6, 22.04 before 22.04.4, and 22.10 before 22.10.1 allows unsafe font upload for skins. A particularly structured XML file could allow one to traverse the server to obtain access to secure files or cause code execution based on the payload.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-45133?
CVE-2022-45133 is rated as a high severity vulnerability due to its potential for code execution and unauthorized file access.
How do I fix CVE-2022-45133?
To fix CVE-2022-45133, upgrade Mahara to versions 21.10.6, 22.04.4, or 22.10.1 or later.
What types of attacks are possible due to CVE-2022-45133?
CVE-2022-45133 allows attackers to upload unsafe fonts that can lead to server traversal and code execution.
Which versions of Mahara are affected by CVE-2022-45133?
CVE-2022-45133 affects Mahara versions prior to 21.10.6, 22.04.4, and 22.10.1.
Is user data at risk because of CVE-2022-45133?
Yes, CVE-2022-45133 poses a risk to user data by enabling unauthorized access to secure files on the server.