CVE-2024-39335: Infoleak
Published Aug 26, 2025
·Updated
Supported versions of Mahara 24.04 before 24.04.1 and 23.04 before 23.04.6 are vulnerable to information being disclosed to an institution administrator under certain conditions via the 'Current submissions' page: Administration -> Groups -> Submissions.
Affected Software
4 affected components
Mahara Mahara<24.04.1
Mahara Mahara<23.04.6
Mahara Mahara>=23.04.0<23.04.6
Mahara Mahara>=24.04.0<24.04.1
Event History
Aug 26, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-39335?
CVE-2024-39335 has been classified as a medium severity vulnerability due to the potential unauthorized information disclosure.
2
How do I fix CVE-2024-39335?
To fix CVE-2024-39335, upgrade Mahara to version 24.04.1 or 23.04.6 or later.
3
What versions are affected by CVE-2024-39335?
CVE-2024-39335 affects Mahara versions before 24.04.1 and 23.04 before 23.04.6.
4
What type of information can be disclosed in CVE-2024-39335?
CVE-2024-39335 may allow institution administrators to access certain submission details that should be restricted.
5
Where can I find more details about CVE-2024-39335?
Detailed information about CVE-2024-39335 can be found on the Mahara forum.