vendor:
Logs plugin for Craft CMS
by:
Steffen Rogge
3.1
CVSS
MEDIUM
Path Traversal
22
CWE
Product Name: Logs plugin for Craft CMS
Affected Version From: <=3.0.3
Affected Version To: 3.0.3
Patch Exists: YES
Related CWE: CVE-2022-23409
CPE: a:ethercreative:logs
Platforms Tested: Linux
2022
Craft CMS Logs Plugin 3.0.3 – Path Traversal (Authenticated)
Craft CMS Logs Plugin version 3.0.3 allows an authenticated attacker to perform path traversal by exploiting a lack of proper validation in the log file reading functionality. This can lead to the unauthorized access of arbitrary files on the underlying file system with the permissions of the web service user. This has been assigned CVE-2022-23409.
Mitigation:
Users should upgrade to version 3.0.4 or later to prevent this vulnerability.