CVE-2021-43264: Path Traversal
In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, adjusting the path component for the page help file allows attackers to bypass the intended access control for HTML files via directory traversal. It replaces the - character with the / character.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-43264?
CVE-2021-43264 is a vulnerability in Mahara before versions 20.04.5, 20.10.3, 21.04.2, and 21.10.0 that allows attackers to bypass access control for HTML files via directory traversal.
How does CVE-2021-43264 work?
CVE-2021-43264 works by adjusting the path component for the page help file and replacing the - character with the / character, allowing attackers to bypass the intended access control.
What is the severity of CVE-2021-43264?
The severity of CVE-2021-43264 is rated as low with a score of 3.3.
Which versions of Mahara are affected by CVE-2021-43264?
Mahara versions before 20.04.5, 20.10.3, 21.04.2, and 21.10.0 are affected by CVE-2021-43264.
How can I fix CVE-2021-43264?
To fix CVE-2021-43264, you should update Mahara to versions 20.04.5, 20.10.3, 21.04.2, or 21.10.0.