CVE-2025-59308 PUBLISHED

Assigner: mitre
Reserved: 12.09.2025 Published: 24.04.2026 Updated: 24.04.2026

In Mahara before 24.04.10 and 25 before 25.04.1, an institution administrator or institution support administrator on a multi-tenanted site can masquerade as an institution member in an institution for which they are not an administrator, if they also have the 'Site staff' role.

Product Status

Vendor n/a
Product n/a
Versions
  • Version n/a is affected

References

Problem Types

  • n/a text