High severity7.3NVD Advisory· Published Nov 2, 2021· Updated Jun 17, 2026
CVE-2021-43266
CVE-2021-43266
Description
In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, exporting collections via PDF export could lead to code execution via shell metacharacters in a collection name. Additional, in Mahara before 20.10.4, 21.04.3, and 21.10.1, exporting collections via PDF export could cause code execution
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:mahara:mahara:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:mahara:mahara:*:*:*:*:*:*:*:*range: >=20.04.0,<20.04.5
- (no CPE)range: <20.04.5, <20.10.3, <21.04.2, <21.10.0, <20.10.4, <21.04.3, <21.10.1
- Mahara/Maharadescription
Patches
Vulnerability mechanics
References
4- bugs.launchpad.net/mahara/+bug/1942903nvdExploitThird Party Advisory
- bugs.launchpad.net/mahara/+bug/1949527nvdThird Party Advisory
- mahara.org/interaction/forum/topic.phpnvdVendor Advisory
- mahara.org/interaction/forum/topic.phpnvdVendor Advisory
News mentions
0No linked articles in our index yet.