CVE-2021-27916 - CVE House
Back to Database
Status published High CVE-2021-27916

Relative Path Traversal / Arbitrary File Deletion in Mautic (GrapesJS Builder)

Vulnerability Description

Prior to the patched version, logged in users of Mautic are vulnerable to Relative Path Traversal/Arbitrary File Deletion. Regardless of the level of access the Mautic user had, they could delete files other than those in the media folders such as system files, libraries or other important files. This vulnerability exists in the implementation of the GrapesJS builder in Mautic.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-27916

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Mattias Michaux
  • Lenon Leite
  • Adrian Schimpf
  • Avikarsha Saha
  • John Linhart

Affected Vendor

Affected Software

Mautic
Vulnerable Versions:
>= 3.3.0, >= 5.0.0

Timeline

Official Publish: September 17th, 2024
Last Modified: September 18th, 2024
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

Weaknesses (CWE)