CVE-2021-43264

LOW

Mahara <20.04.5, 20.10.3, 21.04.2, 21.10.0 - Path Traversal

Title source: llm
STIX 2.1

Description

In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, adjusting the path component for the page help file allows attackers to bypass the intended access control for HTML files via directory traversal. It replaces the - character with the / character.

References (2)

Core 2
Core References
Exploit, Third Party Advisory x_refsource_misc
https://bugs.launchpad.net/mahara/+bug/1944979

Scores

CVSS v3 3.3
EPSS 0.0054
EPSS Percentile 41.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-22
Status published
Products (1)
mahara/mahara 20.04.0 - 20.04.5
Published Nov 02, 2021
Tracked Since Feb 18, 2026