Mahara 21.04 before 21.04.7, 21.10 before 21.10.5, 22.04 before 22.04.3, and 22.10 before 22.10.0 potentially allow a PDF export to trigger a remote shell if the site is running on Ubuntu and the flag -dSAFER is not set with Ghostscript.
History

Fri, 02 May 2025 19:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-250
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2022-11-06T00:00:00.000Z

Updated: 2025-05-02T18:37:16.148Z

Reserved: 2022-11-01T00:00:00.000Z

Link: CVE-2022-44544

cve-icon Vulnrichment

Updated: 2024-08-03T13:54:03.669Z

cve-icon NVD

Status : Modified

Published: 2022-11-06T17:15:10.220

Modified: 2025-05-02T19:15:54.950

Link: CVE-2022-44544

cve-icon Redhat

No data.