PT-2022-15980 · Craft Cms · Craft Cms Logs Plugin

Published

2022-01-31

·

Updated

2022-02-04

·

CVE-2022-23409

CVSS v3.1

4.9

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Craft CMS Logs plugin versions prior to 3.0.4
Description The issue allows remote attackers to read arbitrary files via input to actionStream in Controller.php. This can be exploited by providing malicious input to the actionStream endpoint, potentially leading to unauthorized access to sensitive files.
Recommendations For versions prior to 3.0.4, update to version 3.0.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the actionStream endpoint in Controller.php to minimize the risk of exploitation.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-23409
GHSA-9CHX-2VQW-8VQ5

Affected Products

Craft Cms Logs Plugin