CVE-2022-45134: Critical severity Mahara Mahara vulnerability
Published Aug 22, 2025
·Updated
Mahara 21.10 before 21.10.6, 22.04 before 22.04.4, and 22.10 before 22.10.1 deserializes user input unsafely during skin import. A particularly structured XML file could cause code execution when being processed.
Affected Software
6 affected components
Mahara Mahara<21.10.6
Mahara Mahara<22.04.4
Mahara Mahara<22.10.1
Mahara Mahara>=21.10.0<21.10.6
Mahara Mahara>=22.04.0<22.04.4
Mahara Mahara>=22.10.0<22.10.1
Event History
Aug 22, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-45134?
CVE-2022-45134 has a critical severity level due to potential code execution risk from unsafe deserialization.
2
How do I fix CVE-2022-45134?
To fix CVE-2022-45134, upgrade Mahara to version 21.10.6, 22.04.4, or 22.10.1 or later.
3
What versions of Mahara are affected by CVE-2022-45134?
CVE-2022-45134 affects Mahara versions prior to 21.10.6, 22.04.4, and 22.10.1.
4
What causes the vulnerability in CVE-2022-45134?
The vulnerability in CVE-2022-45134 is caused by the unsafe deserialization of user input during skin imports.
5
Is it possible to exploit CVE-2022-45134?
Yes, CVE-2022-45134 can be exploited by using a specially crafted XML file to achieve code execution.