Forums | Mahara Community

Security Announcements /
PDF export cause code execution in Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0

This topic is closed. Only moderators and the group administrators can post new replies.
Robert Lyon's profile picture
Posts: 756

29 October 2021, 17:02

Vulnerability type: Code execution
Attack type: Local
Impact: Ability to gain privileges

Affected components: Exporting of collections with PDF export enabled
Attack vectors: If a person names a collection in a certain way then on exporting it can cause the name to be executed as a command.

Description: In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, exporting collections via PDF export could cause code execution.

Reported by: Dominic Couture
Bug report:
CVE reference: 2021-43266

Edits to this post:

1 result