Path Traversal Vulnerability in olajowon Loggrove Product
CVE-2025-1228
Key Information:
- Vendor
- Olajowon
- Status
- Loggrove
- Vendor
- CVE Published:
- 12 February 2025
Badges
Summary
A vulnerability has been identified in olajowon Loggrove, specifically in the Logfile Update Handler. The affected function can be manipulated via the argument path in the URL, leading to path traversal issues. This vulnerability enables an attacker to access files outside the intended directory structure, potentially allowing sensitive information to be leaked. The issue can be exploited remotely, heightening its severity for users who have not implemented necessary protections. Continuous delivery with rolling releases complicates vulnerability management, as affected and updated versions lack precise documentation.
Affected Version(s)
Loggrove e428fac38cc480f011afcb1d8ce6c2bad378ddd6
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved