9.8
CVSSv3

CVE-2021-26293

Published: 04/03/2021 Updated: 11/03/2021
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

An issue exists in AfterLogic Aurora up to and including 8.5.3 and WebMail Pro up to and including 8.5.3, when DAV is enabled. They allow directory traversal to create new files (such as an executable file under the web root). This is related to DAVServer.php in 8.x and DAV/Server.php in 7.x.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

afterlogic aurora

afterlogic webmail pro

Github Repositories

AfterLogic Products Vulnerabilities

AfterLogic related CVEs discovered by E3SEC CVE-2021-26292 - Public Full Path Disclosure on AfterLogic Aurora & WebMail Pro WebDAV EndPoint CVE-2021-26293 - [98 CRITICAL] RCE via Public unrestricted upload with path traversal on AfterLogic Aurora & WebMail Pro WebDAV EndPoint CVE-2021-26294 - [75 HIGH] Exposure of sensitive information to an unauthorized