High severity7.5NVD Advisory· Published Jun 20, 2022· Updated Jun 17, 2026
CVE-2022-33913
CVE-2022-33913
Description
In Mahara 21.04 before 21.04.6, 21.10 before 21.10.4, and 22.04.2, files can sometimes be downloaded through thumb.php with no permission check.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4cpe:2.3:a:mahara:mahara:*:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:a:mahara:mahara:*:*:*:*:*:*:*:*range: >=21.04.0,<21.04.6
- cpe:2.3:a:mahara:mahara:22.04.2:*:*:*:*:*:*:*
- (no CPE)
- (no CPE)range: <=21.04.5, <=21.10.3, =22.04.2
Patches
Vulnerability mechanics
References
1- mahara.org/interaction/forum/topic.phpnvdExploitIssue TrackingThird Party AdvisoryVendor Advisory
News mentions
0No linked articles in our index yet.