In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, exporting collections via PDF export could lead to code execution via shell metacharacters in a collection name. Additional, in Mahara before 20.10.4, 21.04.3, and 21.10.1, exporting collections via PDF export could cause code execution
2021-11-02T22:15:09.103
2024-11-21T06:28:57.177
Modified
CVSSv3.1: 7.3 (HIGH)
AV:N/AC:H/Au:S/C:P/I:P/A:P
3.9
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | mahara | mahara | < 20.04.5 | Yes |
Application | mahara | mahara | < 20.10.3 | Yes |
Application | mahara | mahara | < 21.04.2 | Yes |
Application | mahara | mahara | < 20.10.4 | Yes |
Application | mahara | mahara | < 21.04.3 | Yes |
Application | mahara | mahara | < 21.10.1 | Yes |