CVE-2022-23409
MEDIUMEthercreative Logs < 3.0.4 - Path Traversal
Title source: ruleDescription
The Logs plugin before 3.0.4 for Craft CMS allows remote attackers to read arbitrary files via input to actionStream in Controller.php.
Exploits (1)
Scores
CVSS v3
4.9
EPSS
0.0369
EPSS Percentile
88.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Details
CWE
CWE-22
Status
published
Products (2)
ether/logs
0 - 3.0.4Packagist
ethercreative/logs
< 3.0.4
Published
Jan 31, 2022
Tracked Since
Feb 18, 2026