CVE-2022-24694

EUVD-2022-29561
In Mahara 20.10 before 20.10.4, 21.04 before 21.04.3, and 21.10 before 21.10.1, the names of folders in the Files area can be seen by a person not owning the folders. (Only folder names are affected. Neither file names nor file contents are affected.)
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.3 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 40%
Affected Products (NVD)
VendorProductVersion
maharamahara
20.10.0 ≤
𝑥
< 20.10.4
maharamahara
21.04.0 ≤
𝑥
< 21.04.3
maharamahara
21.10.0
maharamahara
21.10.0:rc1
maharamahara
21.10.0:rc2
𝑥
= Vulnerable software versions