CVE-2025-59308: Medium severity Mahara Mahara vulnerability

Published Apr 24, 2026
·
Updated

In Mahara before 24.04.10 and 25 before 25.04.1, an institution administrator or institution support administrator on a multi-tenanted site can masquerade as an institution member in an institution for which they are not an administrator, if they also have the 'Site staff' role.

Affected Software

1 affected component
Mahara Mahara<24.04.10, <25.04.1

Event History

Apr 24, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:16 PM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-59308?

The severity of CVE-2025-59308 is categorized as medium with a CVSS score of 4.7.

2

How do I fix CVE-2025-59308?

To fix CVE-2025-59308, upgrade to Mahara version 24.04.10 or 25.04.1 or later.

3

Who is affected by CVE-2025-59308?

CVE-2025-59308 affects institution administrators and institution support administrators with the 'Site staff' role on multi-tenanted Mahara sites.

4

What are the implications of CVE-2025-59308?

CVE-2025-59308 allows an administrator to impersonate other institution members, potentially compromising user privacy and data security.

5

When was CVE-2025-59308 published?

CVE-2025-59308 was published on April 24, 2026.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203