CyberRota Analysis
AI-GeneratedMahara versions prior to 25.04.5 and 26.04.0 are susceptible to unauthorized access to internal accounts through Learning Tools Interoperability (LTI) under specific conditions affecting both LTI 1.1 and LTI 1.3 Advantage. This vulnerability could allow attackers to gain access to sensitive user information and internal functionalities. Organizations using these versions of Mahara, especially those implementing LTI integrations, should prioritize applying the necessary updates to mitigate potential risks.
Original NVD Description
Mahara before 25.04.5 and 26.04.0 is vulnerable to unauthorized access to internal accounts via Learning Tools Interoperability (LTI) under certain circumstances. This applies to LTI 1.1 and LTI 1.3 Advantage.