Description
Mahara before 25.04.5 and 26.04.0 is vulnerable in the Text block/section functionality when a call is crafted in a certain way that allows it to recall the backed-up content from another Text section.
CVSS 9.8EPSS 0.307%Risk 1.01
View source- Published
- 2026-08-17 23:16:52
- Affected versions
- <25.04.5, <26.04.0
- Type
- Web application
- Last modified
- 2026-08-18 13:17:23
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H