CVE-2022-45134 is a critical deserialization vulnerability affecting Mahara versions 21.10 (before 21.10.6), 22.04 (before 22.04.4), and 22.10 (before 22.10.1). This flaw allows for remote code execution through the unsafe deserialization of user-supplied XML during skin import. With a CVSS score of 9.8, it presents a severe risk due to its network-based attack vector, low complexity, and complete compromise potential (Confidentiality, Integrity, Availability). While there is no evidence of active exploitation, public exploit code, or KEV listing, the vulnerability has garnered significant community discussion, indicating awareness within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 21.10.0, < 21.10.6CPE matchmatch criteria | cpe:2.3:a:mahara:mahara:*:*:*:*:*:*:*:* | ||
>= 22.04.0, < 22.04.4CPE matchmatch criteria | cpe:2.3:a:mahara:mahara:*:*:*:*:*:*:*:* | ||
>= 22.10.0, < 22.10.1CPE matchmatch criteria | cpe:2.3:a:mahara:mahara:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.