Directory Traversal Vulnerability in AfterLogic Aurora and WebMail Pro
CVE-2021-26294
Key Information:
- Vendor
Afterlogic
- Status
- Vendor
- CVE Published:
- 7 March 2021
Badges
What is CVE-2021-26294?
A security flaw was identified in AfterLogic Aurora and WebMail Pro versions up to 7.7.9, allowing unauthorized users to exploit directory traversal. This vulnerability can lead to the exposure of sensitive information, such as configuration files that contain admin panel credentials. An attacker can manipulate requests to access restricted files, which potentially compromises the security of affected systems. It is recommended that users apply available patches and implement security measures to mitigate risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
EPSS Score
92% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
- π‘
Public PoC available
- πΎ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
