Medium severity5.3NVD Advisory· Published Feb 10, 2022· Updated Jun 17, 2026
CVE-2022-24111
CVE-2022-24111
Description
In Mahara 21.04 before 21.04.3 and 21.10 before 21.10.1, portfolios created in groups that have not been shared with non-group members and portfolios created on the site and institution levels can be viewed without requiring a login if the URL to these portfolios is known.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4cpe:2.3:a:mahara:mahara:*:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:a:mahara:mahara:*:*:*:*:*:*:*:*range: >=21.04.0,<21.04.3
- cpe:2.3:a:mahara:mahara:21.10.0:*:*:*:*:*:*:*
- (no CPE)
- (no CPE)range: <21.04.3, <21.10.1
Patches
Vulnerability mechanics
References
2- bugs.launchpad.net/mahara/+bug/1959146nvdThird Party Advisory
- mahara.org/interaction/forum/topic.phpnvdVendor Advisory
News mentions
0No linked articles in our index yet.