CVE-2025-29992

Mahara before 24.04.9 exposes database connection information if the database becomes unreachable, e.g., due to the database server being temporarily down or too busy.
Configurations

Configuration 1 (hide)

cpe:2.3:a:mahara:mahara:*:*:*:*:*:*:*:*

History

05 Sep 2025, 17:02

Type Values Removed Values Added
References () https://mahara.org/THE-FINAL-URL-IN-QUESTION - () https://mahara.org/THE-FINAL-URL-IN-QUESTION - Broken Link
References () https://mahara.org/interaction/forum/topic.php?id=9711 - () https://mahara.org/interaction/forum/topic.php?id=9711 - Vendor Advisory
CPE cpe:2.3:a:mahara:mahara:*:*:*:*:*:*:*:*
First Time Mahara
Mahara mahara

27 Aug 2025, 15:15

Type Values Removed Values Added
Summary
  • (es) Mahara anterior al 24.04.9 expone información de conexión de la base de datos si la base de datos se vuelve inaccesible, por ejemplo, debido a que el servidor de la base de datos está temporalmente inactivo o demasiado ocupado.
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
CWE CWE-200

26 Aug 2025, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-26 14:15

Updated : 2025-09-05 17:02


NVD link : CVE-2025-29992

Mitre link : CVE-2025-29992

CVE.ORG link : CVE-2025-29992


JSON object : View

Products Affected

mahara

  • mahara
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor