Description
In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, adjusting the path component for the page help file allows attackers to bypass the intended access control for HTML files via directory traversal. It replaces the - character with the / character.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-30208 | In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, adjusting the path component for the page help file allows attackers to bypass the intended access control for HTML files via directory traversal. It replaces the - character with the / character. |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T03:55:28.151Z
Reserved: 2021-11-02T00:00:00.000Z
Link: CVE-2021-43264
No data.
Status : Modified
Published: 2021-11-02T22:15:09.027
Modified: 2024-11-21T06:28:56.827
Link: CVE-2021-43264
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD