Path Traversal Vulnerability in ProjeQtor by ProjeQtor
CVE-2026-41465
Key Information:
Badges
What is CVE-2026-41465?
The ProjeQtor application versions 7.0 to 12.4.3 has a vulnerability in its log file viewer located at dynamicDialog.php. This vulnerability allows authenticated attackers to exploit the logname parameter, which fails to properly validate input against directory traversal sequences. By injecting sequences such as '../', attackers can potentially access arbitrary log files on the web server's filesystem. This unauthorized file access could lead to exposure of sensitive information, posing a significant risk to data integrity and confidentiality.
Affected Version(s)
ProjeQtor 7.0 <= 12.4.3
ProjeQtor 12.4.4
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved
