7.1
/ 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Description
ProjeQtor versions 7.0 through 12.4.3 contains a path traversal vulnerability in the log file viewer at dynamicDialog.php where the logname parameter is not validated against directory traversal sequences before constructing file paths. Authenticated attackers can inject directory traversal sequences ../ into the logname parameter to read arbitrary .log files accessible to the web server process on the filesystem.
Basic Information
ID
CVE-2026-41465
Source
VulnCheck
Published
Apr 27, 2026 at 15:10
Modified
Apr 27, 2026 at 16:26
Affected Product
Vendor
ProjeQtor
Product
ProjeQtor
Version
7.0
Affected Versions
ProjeQtor ProjeQtor 7.0