CVE-2022-24694
 
Severity Score
4.3
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
1
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
In Mahara 20.10 before 20.10.4, 21.04 before 21.04.3, and 21.10 before 21.10.1, the names of folders in the Files area can be seen by a person not owning the folders. (Only folder names are affected. Neither file names nor file contents are affected.)
En Mahara versiones 20.10 anteriores a 20.10.4, versiones 21.04 anteriores a 21.04.3 y versiones 21.10 anteriores a 21.10.1, los nombres de las carpetas en el área de Archivos pueden ser visualizados por una persona que no sea propietaria de las carpetas. (Sólo están afectados los nombres de las carpetas. No están afectados ni los nombres de los archivos ni su contenido)
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2022-02-09 CVE Reserved
- 2022-02-09 CVE Published
- 2023-09-01 EPSS Updated
- 2024-08-03 CVE Updated
- 2024-08-03 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-552: Files or Directories Accessible to External Parties
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://bugs.launchpad.net/mahara/+bug/1952808 | 2024-08-03 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://mahara.org/interaction/forum/topic.php?id=8994 | 2022-02-11 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Mahara Search vendor "Mahara" | Mahara Search vendor "Mahara" for product "Mahara" | >= 20.10.0 < 20.10.4 Search vendor "Mahara" for product "Mahara" and version " >= 20.10.0 < 20.10.4" | - |
Affected
| ||||||
Mahara Search vendor "Mahara" | Mahara Search vendor "Mahara" for product "Mahara" | >= 21.04.0 < 21.04.3 Search vendor "Mahara" for product "Mahara" and version " >= 21.04.0 < 21.04.3" | - |
Affected
| ||||||
Mahara Search vendor "Mahara" | Mahara Search vendor "Mahara" for product "Mahara" | 21.10.0 Search vendor "Mahara" for product "Mahara" and version "21.10.0" | - |
Affected
| ||||||
Mahara Search vendor "Mahara" | Mahara Search vendor "Mahara" for product "Mahara" | 21.10.0 Search vendor "Mahara" for product "Mahara" and version "21.10.0" | rc1 |
Affected
| ||||||
Mahara Search vendor "Mahara" | Mahara Search vendor "Mahara" for product "Mahara" | 21.10.0 Search vendor "Mahara" for product "Mahara" and version "21.10.0" | rc2 |
Affected
|