CVE-2024-47192: Medium severity Mahara Mahara vulnerability
Published Aug 26, 2025
·Updated
An issue was discovered in Mahara 23.04.8 and 24.04.4. The use of a malicious export download URL can allow an attacker to download files that they do not have permission to download.
Affected Software
3 affected components
Mahara Mahara>=23.04.8<=24.04.4
Mahara Mahara<23.04.9
Mahara Mahara>=24.04.0<24.04.5
Event History
Aug 26, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-47192?
CVE-2024-47192 has a high severity rating as it allows unauthorized file downloads through a manipulated URL.
2
How do I fix CVE-2024-47192?
To mitigate CVE-2024-47192, upgrade to the latest versions of Mahara beyond 24.04.4 and 23.04.8.
3
What versions of Mahara are affected by CVE-2024-47192?
CVE-2024-47192 affects Mahara versions 23.04.8 and 24.04.4.
4
What kind of attack is possible with CVE-2024-47192?
An attacker can exploit CVE-2024-47192 to download files without proper permissions using a malicious export download URL.
5
Is there a workaround for CVE-2024-47192 until I can upgrade?
Disabling file download features for unauthorized users can serve as a temporary workaround for CVE-2024-47192.