CVE-2024-47853: Mahara
High severity, CVSS 8.8. EPSS: 0.3% chance of exploitation in the next 30 days.
An issue was discovered in Mahara 23.04.8 and 24.04.4. Attackers may utilize escalation of privileges in certain cases when logging into Mahara with Learning Tools Interoperability (LTI).
Affected products
- Mahara Mahara: before 23.04.9 (fixed in 23.04.9); from 24.04.0, before 24.04.5 (fixed in 24.04.5)
Published 2025-08-26. Last modified 2026-06-17.