An issue was discovered in Mahara 23.04.8 and 24.04.4. The use of a malicious export download URL can allow an attacker to download files that they do not have permission to download.
The product downloads source code or an executable from a remote location and executes the code without sufficiently verifying the origin and integrity of the code.