The Logs plugin before 3.0.4 for Craft CMS allows remote attackers to read arbitrary files via input to actionStream in Controller.php.
References
Link Resource
http://packetstormsecurity.com/files/165706/Ethercreative-Logs-3.0.3-Path-Traversal.html Exploit Third Party Advisory VDB Entry
https://plugins.craftcms.com/logs Product Third Party Advisory
https://sec-consult.com/vulnerability-lab/ Exploit Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2022-01-31T07:04:50

Updated: 2022-01-31T07:04:50

Reserved: 2022-01-18T00:00:00


Link: CVE-2022-23409

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2022-01-31T08:15:07.347

Modified: 2022-02-04T19:51:48.140


Link: CVE-2022-23409

JSON object: View

cve-icon Redhat Information

No data.

CWE