Vulnerability Description
ProjeQtor versions 7.0 through 12.4.3 contains a path traversal vulnerability in the log file viewer at dynamicDialog.php where the logname parameter is not validated against directory traversal sequences before constructing file paths. Authenticated attackers can inject directory traversal sequences ../ into the logname parameter to read arbitrary .log files accessible to the web server process on the filesystem.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://damiri.fr/en/cves/CVE-2026-41465
- https://gryfman.fr/cves/CVE-2026-41465
- https://www.projeqtor.com
- https://www.vulncheck.com/advisories/projeqtor-path-traversal-via-dynamicdialog-
FAQ
What is CVE-2026-41465?
CVE-2026-41465 is a vulnerability with a CVSS score of 6.5 (MEDIUM). ProjeQtor versions 7.0 through 12.4.3 contains a path traversal vulnerability in the log file viewer at dynamicDialog.php where the logname parameter is not validated against directory traversal seque...
How severe is CVE-2026-41465?
CVE-2026-41465 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-41465?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.