Afterlogic Aurora and Webmail Pro <= v67.7.9 - Unauthorised Administrative Login due to Retrieval of Credentials via Path Traversal Exploit (CVE-2021-26294)

Description

An issue was discovered in AfterLogic Aurora through 7.7.9 and WebMail Pro through 7.7.9.

The products allow directory traversal to read files (such as a data/settings/settings.xml file containing admin panel credentials), as demonstrated by dav/server.php/files/personal/%2e%2e when using the caldav_public_user account (with caldav_public_user as its password).

This vulnerability was reported to have been exploited 'in the wild' during February 2025.

Remediation

Update to the latest version.

Risk

Impact
High
Probability
Critical
CVSS v4 Score
9.3 / 10
CVSS v3 Score
9.8 / 10
CVSS v2 Score
10 / 10
EPSS
87.9 %

Versions

Information

Category
Path Traversal
CWE
  • CWE-22
  • CWE-257
  • CWE-522
Known Exploitation Activity
No exploitations reported

OWASP

OWASP 2013
A7 - Missing Function Level Access Control
OWASP 2017
A5 - Broken Access Control
OWASP 2021
A1 - Broken Access Control