High severity7.5NVD Advisory· Published Mar 7, 2021· Updated Jun 17, 2026
CVE-2021-26294
CVE-2021-26294
Description
An issue was discovered in AfterLogic Aurora through 7.7.9 and WebMail Pro through 7.7.9. They allow directory traversal to read files (such as a data/settings/settings.xml file containing admin panel credentials), as demonstrated by dav/server.php/files/personal/%2e%2e when using the caldav_public_user account (with caldav_public_user as its password).
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5cpe:2.3:a:afterlogic:aurora:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:afterlogic:aurora:*:*:*:*:*:*:*:*range: <=7.7.9
- (no CPE)range: <=7.7.9
cpe:2.3:a:afterlogic:webmail_pro:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:afterlogic:webmail_pro:*:*:*:*:*:*:*:*range: <=7.7.9
- (no CPE)range: <=7.7.9
- AfterLogic/Auroradescription
Patches
Vulnerability mechanics
References
1- github.com/E3SEC/AfterLogic/blob/main/CVE-2021-26294-exposure-of-sensitive-information-vulnerability.mdnvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.