ProjeQtor versions 7.0 through 12.4.3 contains a path traversal vulnerability in the log file viewer at dynamicDialog.php where the logname parameter is not validated against directory traversal sequences before constructing file paths. Authenticated attackers can inject directory traversal sequences ../ into the logname parameter to read arbitrary .log files accessible to the web server process on the filesystem.
Metrics
Affected Vendors & Products
References
History
Mon, 27 Apr 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ProjeQtor versions 7.0 through 12.4.3 contains a path traversal vulnerability in the log file viewer at dynamicDialog.php where the logname parameter is not validated against directory traversal sequences before constructing file paths. Authenticated attackers can inject directory traversal sequences ../ into the logname parameter to read arbitrary .log files accessible to the web server process on the filesystem. | |
| Title | ProjeQtor < 12.4.4 Path Traversal via dynamicDialog.php | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-04-27T16:26:05.274Z
Reserved: 2026-04-20T16:07:47.311Z
Link: CVE-2026-41465
No data.
Status : Received
Published: 2026-04-27T16:16:45.793
Modified: 2026-04-27T16:16:45.793
Link: CVE-2026-41465
No data.
OpenCVE Enrichment
No data.