In Mahara 21.04 before 21.04.6, 21.10 before 21.10.4, and...
High severity
Unreviewed
Published
Jun 21, 2022
to the GitHub Advisory Database
•
Updated Jan 27, 2023
Description
Published by the National Vulnerability Database
Jun 20, 2022
Published to the GitHub Advisory Database
Jun 21, 2022
Last updated
Jan 27, 2023
In Mahara 21.04 before 21.04.6, 21.10 before 21.10.4, and 22.04.2, files can sometimes be downloaded through thumb.php with no permission check.
References