{"id":"CVE-2021-43266","details":"In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, exporting collections via PDF export could lead to code execution via shell metacharacters in a collection name. Additional, in Mahara before 20.10.4, 21.04.3, and 21.10.1, exporting collections via PDF export could cause code execution","modified":"2026-04-10T04:39:53.978905Z","published":"2021-11-02T22:15:09.103Z","references":[{"type":"ADVISORY","url":"https://bugs.launchpad.net/mahara/+bug/1949527"},{"type":"ADVISORY","url":"https://mahara.org/interaction/forum/topic.php?id=8952"},{"type":"ADVISORY","url":"https://mahara.org/interaction/forum/topic.php?id=8995"},{"type":"EVIDENCE","url":"https://bugs.launchpad.net/mahara/+bug/1942903"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/maharaproject/mahara","events":[{"introduced":"0ac1f94a973e467134edc7b94cb65318eb19227f"},{"fixed":"84bc4a5c7030470a811a630b242066df098ec273"},{"introduced":"baa466e351a72541cd7a28d6eb982a1fbc7a428c"},{"fixed":"d294a69446e795dcbddf4e4929d597968bbdc4ef"},{"introduced":"359597b32c7afe52339422a91f14256e17b33dfc"},{"fixed":"0c3426bf91635a3e33c4cda993af52318e123d9a"},{"introduced":"baa466e351a72541cd7a28d6eb982a1fbc7a428c"},{"fixed":"575cea51bb6c07acf0166da95e26595d03ead13f"},{"introduced":"359597b32c7afe52339422a91f14256e17b33dfc"},{"fixed":"52109b30a7a9fa34ccd79bffe1ec42df3e9d3cc7"},{"introduced":"9b0da78a1f8585b142a372d422bf5d9a36e1450d"},{"fixed":"25ec8c4ffc820c2871ed1dc5a1b3008b8465edf3"}],"database_specific":{"versions":[{"introduced":"20.04.0"},{"fixed":"20.04.5"},{"introduced":"20.10.0"},{"fixed":"20.10.3"},{"introduced":"21.04.0"},{"fixed":"21.04.2"},{"introduced":"20.10.0"},{"fixed":"20.10.4"},{"introduced":"21.04.0"},{"fixed":"21.04.3"},{"introduced":"21.10.0"},{"fixed":"21.10.1"}]}}],"versions":["20.04.0_RELEASE","20.04.1_RELEASE","20.04.2_RELEASE","20.04.3_RELEASE","20.04.4_RELEASE","20.10.0_RELEASE","20.10.1_RELEASE","20.10.2_RELEASE","20.10.3_RELEASE","21.04.0_RELEASE","21.04.1_RELEASE","21.04.2_RELEASE","21.10.0_RELEASE"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-43266.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"}]}