An issue was discovered in Mahara 23.04.8 and 24.04.4. Attackers may utilize escalation of privileges in certain cases when logging into Mahara with Learning Tools Interoperability (LTI).
History

Mon, 22 Sep 2025 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 05 Sep 2025 17:15:00 +0000

Type Values Removed Values Added
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:mahara:mahara:*:*:*:*:*:*:*:*
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Wed, 27 Aug 2025 11:30:00 +0000

Type Values Removed Values Added
First Time appeared Mahara
Mahara mahara
Vendors & Products Mahara
Mahara mahara

Tue, 26 Aug 2025 14:15:00 +0000

Type Values Removed Values Added
Description An issue was discovered in Mahara 23.04.8 and 24.04.4. Attackers may utilize escalation of privileges in certain cases when logging into Mahara with Learning Tools Interoperability (LTI).
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2025-08-26T00:00:00.000Z

Updated: 2025-09-22T15:34:08.992Z

Reserved: 2024-10-04T00:00:00.000Z

Link: CVE-2024-47853

cve-icon Vulnrichment

Updated: 2025-09-22T15:33:33.084Z

cve-icon NVD

Status : Modified

Published: 2025-08-26T14:15:35.037

Modified: 2025-09-22T16:15:38.153

Link: CVE-2024-47853

cve-icon Redhat

No data.