CVE-2026-41465Disclosure

LOWCVSS 7.1 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

ProjeQtor versions 7.0 through 12.4.3 contain a path traversal vulnerability in the log file viewer at dynamicDialog.php where the logname parameter is not validated against directory traversal sequences before constructing file paths. Authenticated attackers can inject directory traversal sequences ../ into the logname parameter to read arbitrary .log files accessible to the web server process on the filesystem.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-04-27: 2Technical Details · 2026-04-27: 204-27
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-41465 ProjeQtor versions 7.0 through 12.4.3 contains a path traversal vulnerability in the log file viewer at dynamicDialog.php where the logname parameter is not validated… https://www.cve.org/CVERecord?id=CVE-2026-41465

    Post summary

    The post discloses a path traversal flaw in ProjeQtor's log file viewer due to an unvalidated logname parameter, highlighting affected versions 7.0 through 12.4.3 and linking to the CVE record.

    0000072
    57.3K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-41465 Path Traversal in ProjeQtor 7.0 Through 12.4.3 Log File Viewer https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-41465

    Post summary

    The post announces a Path Traversal issue (CVE‑2026‑41465) affecting ProjeQtor Log File Viewer 7.0‑12.4.3, but it lacks details on exploitation, mitigation or proof‑of‑concept.

    0000040
    4.0K followersView on X

Explore more