CVE-2025-59308: Medium severity Mahara Mahara vulnerability
In Mahara before 24.04.10 and 25 before 25.04.1, an institution administrator or institution support administrator on a multi-tenanted site can masquerade as an institution member in an institution for which they are not an administrator, if they also have the 'Site staff' role.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-59308?
The severity of CVE-2025-59308 is categorized as medium with a CVSS score of 4.7.
How do I fix CVE-2025-59308?
To fix CVE-2025-59308, upgrade to Mahara version 24.04.10 or 25.04.1 or later.
Who is affected by CVE-2025-59308?
CVE-2025-59308 affects institution administrators and institution support administrators with the 'Site staff' role on multi-tenanted Mahara sites.
What are the implications of CVE-2025-59308?
CVE-2025-59308 allows an administrator to impersonate other institution members, potentially compromising user privacy and data security.
When was CVE-2025-59308 published?
CVE-2025-59308 was published on April 24, 2026.