Cross-site request forgery (CSRF) vulnerability in Mahara before 1.4.1 allows remote attackers to hijack the authentication of administrators for requests that add a user to an institution.
https://launchpad.net/mahara/+milestone/1.4.1
https://bugs.launchpad.net/mahara/+bug/800032