Critical severity9.1NVD Advisory· Published Aug 26, 2025· Updated Jun 17, 2026
CVE-2024-39335
CVE-2024-39335
Description
Supported versions of Mahara 24.04 before 24.04.1 and 23.04 before 23.04.6 are vulnerable to information being disclosed to an institution administrator under certain conditions via the 'Current submissions' page: Administration -> Groups -> Submissions.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:mahara:mahara:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:mahara:mahara:*:*:*:*:*:*:*:*range: >=23.04.0,<23.04.6
- (no CPE)
- (no CPE)range: 24.04 < 24.04.1, 23.04 < 23.04.6
Patches
Vulnerability mechanics
References
2- mahara.org/interaction/forum/topic.phpnvdVendor Advisory
- mahara.org/interaction/forum/view.phpnvdVendor Advisory
News mentions
0No linked articles in our index yet.