ZeroHour

CVE-2022-23409

PoC ×2
CVSS 3.1
4.9 medium
EPSS
14%p96
Published
()
Modified
Description

The Logs plugin before 3.0.4 for Craft CMS allows remote attackers to read arbitrary files via input to actionStream in Controller.php.

Vendors
ethercreative
Products
logs
Weakness
CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.