ZeroHour

CVE-2021-43264

PoC
CVSS 3.1
3.3 low
EPSS
<1%p45
Published
()
Modified
Description

In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, adjusting the path component for the page help file allows attackers to bypass the intended access control for HTML files via directory traversal. It replaces the - character with the / character.

Vendors
mahara
Products
mahara
Weakness
CWE-22
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.