{"id":"CVE-2021-40849","details":"In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, the account associated with a web services token is vulnerable to being exploited and logged into, resulting in information disclosure (at a minimum) and often escalation of privileges.","modified":"2026-07-08T06:03:34.731329832Z","published":"2021-11-03T11:15:08.310Z","database_specific":{"unresolved_ranges":[{"source":"CPE_STRING","vendor_product":"mahara:mahara","cpes":["cpe:2.3:a:mahara:mahara:21.10.0:rc1:*:*:*:*:*:*","cpe:2.3:a:mahara:mahara:21.10.0:rc2:*:*:*:*:*:*"],"extracted_events":[{"introduced":"21.10.0-rc1"},{"last_affected":"21.10.0-rc1"},{"introduced":"21.10.0-rc2"},{"last_affected":"21.10.0-rc2"}]}]},"references":[{"type":"ADVISORY","url":"https://bugs.launchpad.net/mahara/+bug/1930469"},{"type":"ADVISORY","url":"https://mahara.org/interaction/forum/topic.php?id=8949"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/maharaproject/mahara","events":[{"introduced":"0"},{"fixed":"84bc4a5c7030470a811a630b242066df098ec273"},{"introduced":"baa466e351a72541cd7a28d6eb982a1fbc7a428c"},{"fixed":"d294a69446e795dcbddf4e4929d597968bbdc4ef"},{"introduced":"359597b32c7afe52339422a91f14256e17b33dfc"},{"fixed":"0c3426bf91635a3e33c4cda993af52318e123d9a"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"20.04.5"},{"introduced":"20.10.0"},{"fixed":"20.10.3"},{"introduced":"21.04.0"},{"fixed":"21.04.2"}],"source":"CPE_RANGE","cpe":"cpe:2.3:a:mahara:mahara:*:*:*:*:*:*:*:*"}}],"versions":["20.10.2_RELEASE","20.04.4_RELEASE","21.04.1_RELEASE","20.10.1_RELEASE","20.04.3_RELEASE","21.04.0_RELEASE","20.10.0_RELEASE","20.04.2_RELEASE","20.04.1_RELEASE","20.04.0_RELEASE","20.04RC2_RELEASE","20.04RC1_RELEASE","1.8RC2_RELEASE","1.8RC1_RELEASE","1.7RC1_RELEASE","1.4.0ALPHA1_RELEASE","1.3.0BETA2_RELEASE","1.3.0BETA1_RELEASE","1.2.0ALPHA3_RELEASE","1.2.0ALPHA2_RELEASE","1.1.0BETA4_RELEASE","1.1.0BETA2_RELEASE","1.1.0ALPHA3_RELEASE","1.1.0ALPHA2_RELEASE","1.1.0ALPHA1_RELEASE","1.0.0BETA2_RELEASE","1.0.0ALPHA2_RELEASE","1.0.0ALPHA1_RELEASE"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-40849.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}