An issue was discovered in Mahara 23.04.8 and 24.04.4. The use of a malicious export download URL can allow an attacker to download files that they do not have permission to download.
| Software | From | Fixed in |
|---|---|---|
| mahara / mahara | - | 23.04.9 |
| mahara / mahara | 24.04.0 | 24.04.5 |