CVE-2021-43264

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
02/11/2021
Last modified:
09/11/2021

Description

In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, adjusting the path component for the page help file allows attackers to bypass the intended access control for HTML files via directory traversal. It replaces the - character with the / character.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mahara:mahara:*:*:*:*:*:*:*:* 20.04.0 (including) 20.04.5 (excluding)
cpe:2.3:a:mahara:mahara:*:*:*:*:*:*:*:* 20.10.0 (including) 20.10.3 (excluding)
cpe:2.3:a:mahara:mahara:*:*:*:*:*:*:*:* 21.04.0 (including) 21.04.2 (excluding)