Mahara before 20.10.5, 21.04.4, 21.10.2, and 22.04.0 is vulnerable to Cross Site Request Forgery (CSRF) because randomly generated tokens are too easily guessable.
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Link | Tags |
---|---|
https://bugs.launchpad.net/mahara/+bug/1930171 | patch vendor advisory issue tracking |
https://mahara.org/interaction/forum/topic.php?id=9094 | vendor advisory |