Mahara 21.04 before 21.04.7, 21.10 before 21.10.5, 22.04 before 22.04.3, and 22.10 before 22.10.0 potentially allow a PDF export to trigger a remote shell if the site is running on Ubuntu and the flag -dSAFER is not set with Ghostscript.
2022-11-06T17:15:10.220
2025-05-02T19:15:54.950
Modified
CVSSv3.1: 9.8 (CRITICAL)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | mahara | mahara | < 21.04.7 | Yes |
Application | mahara | mahara | < 21.10.5 | Yes |
Application | mahara | mahara | < 22.04.3 | Yes |
Application | mahara | mahara | 22.10.0 | Yes |
Operating System | canonical | ubuntu_linux | 18.04 | No |