
Cloud Vulnerability DB
A community-led vulnerabilities database
An issue was discovered in AfterLogic Aurora through 7.7.9 and WebMail Pro through 7.7.9 that allows directory traversal to read sensitive files. The vulnerability enables unauthorized access to critical system files, including admin panel credentials stored in data/settings/settings.xml, through the WebDAV endpoint (NVD, GitHub Advisory).
The vulnerability exists in the WebDAV endpoint implementation and can be exploited using the built-in caldav_public_user account with its predefined password 'caldav_public_user'. The issue stems from improper input sanitization in dav/server.php, specifically in the exec and httpGet methods, allowing directory traversal via %2e%2e sequences. The vulnerability has been assigned a CVSS v3.1 Base Score of 7.5 (HIGH) with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N, indicating high severity with network accessibility and no authentication required (GitHub Advisory, NVD).
The vulnerability allows attackers to read sensitive configuration files, including database credentials, license keys, and admin panel credentials. This exposure of sensitive information could lead to unauthorized access to the application's administrative functions and potentially compromise the entire system (GitHub Advisory).
The vulnerability is easily exploitable using a simple HTTP GET request to the WebDAV endpoint. An attacker can use the built-in caldav_public_user account with its predefined password to access files through directory traversal. The attack can be performed using a basic curl command targeting the vulnerable endpoint (GitHub Advisory).
Users should upgrade to versions newer than 7.7.9 of AfterLogic Aurora and WebMail Pro to address this vulnerability (NVD).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."