In Mahara 21.04 before 21.04.6, 21.10 before 21.10.4, and 22.04.2, files can sometimes be downloaded through thumb.php with no permission check.
{
"versions": [
{
"introduced": "21.04.0"
},
{
"fixed": "21.04.6"
},
{
"introduced": "21.10.0"
},
{
"fixed": "21.10.4"
},
{
"introduced": "0"
},
{
"last_affected": "22.04.2"
}
]
}