CVE-2022-23409
Published Jan 31, 2022The Logs plugin before 3.0.4 for Craft CMS allows remote attackers to read arbitrary files via input to actionStream in Controller.php.
Vendor/product archive
2 CVEs tagged to ethercreative / logs — 0 Critical, 1 High, 1 Medium, 0 Low, 0 Unrated.
The Logs plugin before 3.0.4 for Craft CMS allows remote attackers to read arbitrary files via input to actionStream in Controller.php.
Ether Logs is a package that allows one to check one's logs in the Craft 3 utilities section. A vulnerability was found in versions prior to 3.0.4 that allowed authenticated admin…