{"id":"CVE-2022-28892","details":"Mahara before 20.10.5, 21.04.4, 21.10.2, and 22.04.0 is vulnerable to Cross Site Request Forgery (CSRF) because randomly generated tokens are too easily guessable.","modified":"2026-08-12T03:51:11.504876209Z","published":"2022-04-28T00:00:00Z","database_specific":{"cna_assigner":"mitre","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/28xxx/CVE-2022-28892.json","unresolved_ranges":[{"source":"DESCRIPTION","extracted_events":[{"fixed":"20.10.5"}]}]},"references":[{"type":"WEB","url":"https://bugs.launchpad.net/mahara/+bug/1930171"},{"type":"WEB","url":"https://mahara.org/interaction/forum/topic.php?id=9094"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/28xxx/CVE-2022-28892.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-28892"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/maharaproject/mahara","events":[{"introduced":"0"},{"fixed":"5e19936332bcbbaf29d6fb5709182076840a83ee"},{"introduced":"359597b32c7afe52339422a91f14256e17b33dfc"},{"fixed":"3785940dbcd2bbdce534dcff7abdc2dd73c1b9ed"},{"introduced":"9b0da78a1f8585b142a372d422bf5d9a36e1450d"},{"fixed":"46808bee1dd5d5c925701d72df235529823eb997"}],"database_specific":{"source":"CPE_RANGE","cpe":"cpe:2.3:a:mahara:mahara:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"20.10.5"},{"introduced":"21.04.0"},{"fixed":"21.04.4"},{"introduced":"21.10.0"},{"fixed":"21.10.2"}]}}],"versions":["21.10.1_RELEASE","21.04.3_RELEASE","20.10.4_RELEASE","20.10.3_RELEASE","21.04.2_RELEASE","21.10.0_RELEASE","20.10.2_RELEASE","21.04.1_RELEASE","20.10.1_RELEASE","21.04.0_RELEASE","20.10.0_RELEASE","20.10RC2_RELEASE","20.10RC1_RELEASE","1.8RC2_RELEASE","1.8RC1_RELEASE","1.7RC1_RELEASE","1.4.0ALPHA1_RELEASE","1.3.0BETA2_RELEASE","1.3.0BETA1_RELEASE","1.2.0ALPHA3_RELEASE","1.2.0ALPHA2_RELEASE","1.1.0BETA4_RELEASE","1.1.0BETA2_RELEASE","1.1.0ALPHA3_RELEASE","1.1.0ALPHA2_RELEASE","1.1.0ALPHA1_RELEASE","1.0.0BETA2_RELEASE","1.0.0ALPHA2_RELEASE","1.0.0ALPHA1_RELEASE"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-28892.json"}}],"schema_version":"1.9.0"}