CVE-2021-43264
LOWMahara <20.04.5, 20.10.3, 21.04.2, 21.10.0 - Path Traversal
Title source: llmDescription
In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, adjusting the path component for the page help file allows attackers to bypass the intended access control for HTML files via directory traversal. It replaces the - character with the / character.
References (2)
Core 2
Core References
Exploit, Third Party Advisory x_refsource_misc
https://bugs.launchpad.net/mahara/+bug/1944979
Vendor Advisory x_refsource_misc
https://mahara.org/interaction/forum/topic.php?id=8954
Scores
CVSS v3
3.3
EPSS
0.0054
EPSS Percentile
41.4%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Details
CWE
CWE-22
Status
published
Products (1)
mahara/mahara
20.04.0 - 20.04.5
Published
Nov 02, 2021
Tracked Since
Feb 18, 2026