packetstormsecurity.com
http://packetstormsecurity.com/files/165706/Ethercreative-Logs-3.0.3-Path-Traversal.html CVE-2022-23409
MEDIUM
Duplicate Advisory: Path Traversal in the Logs plugin for Craft CMS
Record summary
CVE-2022-23409 has a selected CVSS score of 4.9 (medium); EIP currently links 1 catalogued exploit.
Description
The Logs plugin before 3.0.4 for Craft CMS allows remote attackers to read arbitrary files via input to actionStream in Controller.php.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
ether/logsBrowse Packagist / ether/logs | GitHub Advisory | Before 3.0.4 · Fixed in 3.0.4 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBEthercreative Logs 3.0.3 - Path TraversalExploitDB exploitby ub3rsickNot analyzed1 file
References
6github.com
https://github.com/ethercreative/logs github.com
https://github.com/ethercreative/logs/commit/eb225cc78b1123a10ce2784790f232d71c2066c4 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-23409 plugins.craftcms.com
https://plugins.craftcms.com/logs sec-consult.com
https://sec-consult.com/vulnerability-lab