S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Feb 29, 2024

CVE-2021-26294 Scanner

CVE-2021-26294 scanner - Information Disclosure vulnerability in AfterLogic Aurora and WebMail Pro

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3k
Times Used
continuous scan runs
4.1k
Continuously Checked
assets under CS
1
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-26294
7.5
CVSS

An issue was discovered in AfterLogic Aurora through 7.7.9 and WebMail Pro through 7.7.9. They allow directory traversal to read files (such as a data/settings/settings.xml file containing admin panel credentials), as demonstrated by dav/server.php/files/personal/%2e%2e when using the caldav_public_user account (with caldav_public_user as its password).

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 19, 2026View on NVD →
Detail

AfterLogic Aurora and WebMail Pro are comprehensive email and collaboration platforms, designed for both personal and professional use. They offer a wide range of features including email, calendars, contacts, tasks, and file storage. These products are widely adopted by businesses, educational institutions, and individual users for their versatility and ease of integration with existing IT infrastructures. The software is known for its user-friendly interface and robust functionality, making it a popular choice for those seeking efficient communication and organization tools.

Specifically, this vulnerability exploits the WebDAV EndPoint by using a built-in “caldav_public_user@localhost” username and its predefined password. The attack involves crafting a request that navigates beyond the intended web root directory to access and read files, such as the settings.xml file, which contains critical system settings including administrative credentials and database host information. The vulnerability is a direct result of improper validation of user-supplied input in the file path.

Exploitation of this vulnerability can lead to a range of adverse effects including unauthorized access to admin accounts, database theft, and exposure of sensitive information. Attackers can leverage the disclosed information to perform further attacks, such as data breaches, account takeover, and potentially, gain full control over the affected systems. This underscores the criticality of securing web applications against information disclosure vulnerabilities.

By becoming a member of the S4E platform, users gain access to comprehensive security scanning capabilities that can detect vulnerabilities like the one found in AfterLogic Aurora and WebMail Pro. Our platform employs state-of-the-art technology to identify and report security weaknesses, helping users to stay ahead of potential threats. Membership offers not just diagnostic insights but also guidance on best practices and remediation strategies to enhance digital asset security.

 

References

Solution Advice
  1. Upgrade AfterLogic Aurora and WebMail Pro to version 7.7.9 or higher.
  2. Regularly review and update access control settings to limit unnecessary exposure of sensitive files.
  3. Implement strict input validation to prevent unauthorized access through manipulated requests.
  4. Monitor and audit system logs for suspicious activities that may indicate exploitation attempts.
  5. Educate users and administrators on the importance of using strong, unique passwords for all accounts.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.