CVE-2023-47799: Infoleak
Mahara before 22.10.4 and 23.x before 23.04.4 allows information disclosure if the experimental HTML bulk export is used via the administration interface or via the CLI, and the resulting export files are given to the account holders. They may contain images of other account holders because the cache is not cleared after the files of one account are exported.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-47799?
CVE-2023-47799 has been assessed to have a medium severity due to the potential information disclosure.
How do I fix CVE-2023-47799?
To fix CVE-2023-47799, update Mahara to version 22.10.4 or 23.04.4 or later.
What versions of Mahara are affected by CVE-2023-47799?
CVE-2023-47799 affects Mahara versions prior to 22.10.4 and versions prior to 23.04.4.
What type of vulnerability is CVE-2023-47799?
CVE-2023-47799 is an information disclosure vulnerability.
Can I use the experimental HTML bulk export feature with CVE-2023-47799?
Using the experimental HTML bulk export feature in versions affected by CVE-2023-47799 poses a risk of exposing sensitive data from other account holders.