HarborGuard / CVE
Back to search
HIGHCVE-2026-41465Published Modified CNA VulnCheck

CVE-2026-41465: ProjeQtor < 12.4.4 Path Traversal via dynamicDialog.php

ProjeQtor versions 7.0 through 12.4.3 contain a path traversal vulnerability in the log file viewer at dynamicDialog.php where the logname parameter is not validated against directory traversal sequences before constructing file paths. Authenticated attackers can inject directory traversal sequences ../ into the logname parameter to read arbitrary .log files accessible to the web server process on the filesystem.

Metrics

CVSS v4.0
7.1
Severity
HIGH
Fixed in
12.4.4
Affected Products
1

Fix available

12.4.4
Affected packages
  • ProjeQtor / ProjeQtor
    ≤ 12.4.3
    Fixed in 12.4.4
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CVE-2026-41465: ProjeQtor < 12.4.4 Path Traversal via dynamicDialog.php | HarborGuard CVE