Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, adjusting the path component for the page help file allows attackers to bypass the intended access control for HTML files via directory traversal. It replaces the - character with the / character.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Mahara 路径遍历漏洞
Vulnerability Description
Catalyst It Catalyst IT Mahara是新西兰Catalyst IT(Catalyst It)公司的一套社交网络系统。该系统包含博客、履历表生成器、文件管理器等。 Mahara 存在安全漏洞,攻击者可以通过目录遍历绕过对HTML文件的预期访问控制。以下产品及版本受到影响:Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0。
CVSS Information
N/A
Vulnerability Type
N/A