PT-2025-53599 · Unknown · Cola Dnslog

Captaince

·

Published

2025-12-26

·

Updated

2026-01-09

·

CVE-2025-57403

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Cola Dnslog version 1.3.2
Description The application processes DNS queries for TXT records by concatenating the requested URL with a base path using os.path.join. This allows for directory traversal or absolute path injection. Successful exploitation could lead to the exposure of sensitive information. The vulnerable component is the processing of DNS TXT record queries.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Relative Path Traversal

Weakness Enumeration

Related Identifiers

CVE-2025-57403

Affected Products

Cola Dnslog