CVE-2023-47799
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Mahara before 22.10.4 and 23.x before 23.04.4 allows information disclosure if the experimental HTML bulk export is used via the administration interface or via the CLI, and the resulting export files are given to the account holders. They may contain images of other account holders because the cache is not cleared after the files of one account are exported.
Mahara, versiones anteriores a la 22.10.4 y 23.x, versiones anteriores a la 23.04.4, permite la divulgación de información si se utiliza la exportación masiva de HTML experimental a través de la interfaz de administración o la CLI, y los archivos de exportación resultantes se entregan a los titulares de las cuentas. Estos pueden contener imágenes de otros titulares de cuentas, ya que la caché no se borra después de exportar los archivos de una cuenta.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2023-11-10 CVE Reserved
- 2025-08-25 CVE Published
- 2025-09-05 CVE Updated
- 2026-05-11 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
References (2)
| URL | Tag | Source |
|---|---|---|
| https://git.mahara.org/catalyst-security/mahara-security/-/issues/2 | Broken Link |
| URL | Date | SRC |
|---|
| URL | Date | SRC |
|---|
| URL | Date | SRC |
|---|---|---|
| https://mahara.org/interaction/forum/topic.php?id=9353 | 2025-08-25 |
Affected Vendors, Products, and Versions
| Vendor | Product | Version | Other | Status | ||||||
|---|---|---|---|---|---|---|---|---|---|---|
| Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
| Mahara Search vendor "Mahara" | Mahara Search vendor "Mahara" for product "Mahara" | < 22.10.4 Search vendor "Mahara" for product "Mahara" and version " < 22.10.4" | - |
Affected
| ||||||
| Mahara Search vendor "Mahara" | Mahara Search vendor "Mahara" for product "Mahara" | >= 23.04.0 < 23.04.4 Search vendor "Mahara" for product "Mahara" and version " >= 23.04.0 < 23.04.4" | - |
Affected
| ||||||
