CVE-2021-43264 Information
Jun 07, 2022
cve
Description
In Mahara before 20.04.5 20.10.3 21.04.2 and 21.10.0 adjusting the path component for the page help file allows attackers to bypass the intended access control for HTML files via directory traversal. It replaces the - character with the / character.
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Reference
https://bugs.launchpad.net/mahara/+bug/1944979 https://mahara.org/interaction/forum/topic.php?id=8954
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
LOW
Availability Impact
NONE
Base Score
NONE
Base Severity
3.3
Share on: