In Mahara 20.10 before 20.10.4, 21.04 before 21.04.3, and 21.10 before 21.10.1, the names of folders in the Files area can be seen by a person not owning the folders. (Only folder names are affected. Neither file names nor file contents are affected.)
References
Link | Resource |
---|---|
https://bugs.launchpad.net/mahara/+bug/1952808 | Exploit Issue Tracking Third Party Advisory |
https://mahara.org/interaction/forum/topic.php?id=8994 | Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2022-02-09T04:31:50
Updated: 2022-02-10T14:15:19
Reserved: 2022-02-09T00:00:00
Link: CVE-2022-24694
JSON object: View
NVD Information
Status : Analyzed
Published: 2022-02-09T05:15:09.490
Modified: 2022-02-11T20:27:22.350
Link: CVE-2022-24694
JSON object: View
Redhat Information
No data.
CWE