Medium severity4.3NVD Advisory· Published Mar 9, 2020· Updated Jun 17, 2026
CVE-2020-9386
CVE-2020-9386
Description
In Mahara 18.10 before 18.10.5, 19.04 before 19.04.4, and 19.10 before 19.10.2, file metadata information is disclosed to group members in the Elasticsearch result list despite them not having access to that artefact anymore.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:mahara:mahara:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:mahara:mahara:*:*:*:*:*:*:*:*range: >=18.10.0,<18.10.5
- (no CPE)range: <18.10.5, <19.04.4, <19.10.2
- Mahara/Maharadescription
Patches
Vulnerability mechanics
References
2- bugs.launchpad.net/mahara/+bug/1840201nvdIssue TrackingPatchThird Party Advisory
- mahara.org/interaction/forum/topic.phpnvdVendor Advisory
News mentions
0No linked articles in our index yet.