CVE-2021-43266

In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, exporting collections via PDF export could lead to code execution via shell metacharacters in a collection name.

Summary:

In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, exporting collections via PDF export could lead to code execution via shell metacharacters in a collection name.

Reference Links(if available):

  • https://bugs.launchpad.net/mahara/+bug/1942903
  • CVSS Score (if available)

    v2: / MEDIUM

    v3: /

    Links to Exploits(if available)