CVE 7.1 HIGH

ProjeQtor < 12.4.4 Path Traversal via dynamicDialog.php_CVE-2026-41465

7.1 / 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

Description

ProjeQtor versions 7.0 through 12.4.3 contains a path traversal vulnerability in the log file viewer at dynamicDialog.php where the logname parameter is not validated against directory traversal sequences before constructing file paths. Authenticated attackers can inject directory traversal sequences ../ into the logname parameter to read arbitrary .log files accessible to the web server process on the filesystem.

Basic Information

ID CVE-2026-41465
Source VulnCheck
Published Apr 27, 2026 at 15:10
Modified Apr 27, 2026 at 16:26

Affected Product

Vendor ProjeQtor
Product ProjeQtor
Version 7.0
Affected Versions ProjeQtor ProjeQtor 7.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.