OS Command Injection Vulnerability in olajowon Loggrove
CVE-2025-1229
Key Information:
- Vendor
- Olajowon
- Status
- Loggrove
- Vendor
- CVE Published:
- 12 February 2025
Badges
Summary
A vulnerability exists in olajowon Loggrove due to improper handling of user input in the /read/?page=1&logfile=eee&match= endpoint. This flaw allows remote attackers to execute arbitrary OS commands by manipulating the 'path' argument. As the affected versions of Loggrove do not implement versioning, specific release details are unavailable. Publicly disclosed exploitation means that systems running this product are at risk, necessitating immediate protective measures.
Affected Version(s)
Loggrove e428fac38cc480f011afcb1d8ce6c2bad378ddd6
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved