CVE-2021-26294

An issue was discovered in AfterLogic Aurora through 7.7.9 and WebMail Pro through 7.7.9. They allow directory traversal to read files (such as a...

Basic Information

CVE State
PUBLISHED
Reserved Date
January 27, 2021
Published Date
March 07, 2021
Last Updated
August 03, 2024
Vendor
n/a
Product
n/a
Description
An issue was discovered in AfterLogic Aurora through 7.7.9 and WebMail Pro through 7.7.9. They allow directory traversal to read files (such as a data/settings/settings.xml file containing admin panel credentials), as demonstrated by dav/server.php/files/personal/%2e%2e when using the caldav_public_user account (with caldav_public_user as its password).

CVSS Scores

EPSS Score

Score
87.18% (Percentile: 99.38%) as of 2025-04-29

Exploit Status

Exploited in the Wild
Yes (added 2025-04-28 00:00:00 UTC) Source

Known Exploited Vulnerability Information

Source Added Date
The Shadowserver (via CIRCL) 2025-04-28 00:00:00 UTC

Scanner Integrations