CVE-2023-47799

7.5

Mahara · Mahara

Mahara allows unauthorized information disclosure during HTML bulk exports due to improper cache management, potentially exposing images belonging to other account holders.

Executive summary

A vulnerability in Mahara allows for the unauthorized disclosure of sensitive user data, specifically images, during the HTML bulk export process.

Vulnerability

This information disclosure flaw occurs because the system fails to clear the cache after exporting files for a specific account. An attacker can access images of other account holders when the experimental HTML bulk export feature is utilized via the administration interface or CLI.

Business impact

The exploitation of this vulnerability leads to a breach of user privacy and confidentiality, as unauthorized parties may obtain images belonging to other system users. Given the CVSS score of 7.5, this is considered a high severity issue that could lead to significant reputational damage and potential regulatory non-compliance regarding data protection.

Remediation

Immediate Action: Update the Mahara installation to version 22.10.4, 23.04.4, or a subsequent secure release provided by the vendor.

Proactive Monitoring: Review administrative and CLI export logs for suspicious activity or patterns of bulk export execution.

Compensating Controls: Disable the experimental HTML bulk export functionality within the administration interface until the software has been successfully patched.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

This vulnerability presents a clear risk to data privacy within the Mahara platform. Administrators must prioritize the application of the vendor-supplied patches to ensure the cache management issue is resolved, thereby preventing the exposure of sensitive user imagery.

More Mahara CVEs

Sources