CVE-2019-9708: Mahara

Medium severity, CVSS 4.9. EPSS: 1% chance of exploitation in the next 30 days.

An issue was discovered in Mahara 17.10 before 17.10.8, 18.04 before 18.04.4, and 18.10 before 18.10.1. A site administrator can suspend the system user (root), causing all users to be locked out from the system.

Affected products

  • Mahara Mahara: from 17.10.0, before 17.10.8 (fixed in 17.10.8); from 18.04.0, before 18.04.4 (fixed in 18.04.4); from 18.10.0, before 18.10.1 (fixed in 18.10.1)

Published 2019-05-07. Last modified 2026-06-17.