Description
ProjeQtor versions 7.0 through 12.4.3 contains a path traversal vulnerability in the log file viewer at dynamicDialog.php where the logname parameter is not validated against directory traversal sequences before constructing file paths. Authenticated attackers can inject directory traversal sequences ../ into the logname parameter to read arbitrary .log files accessible to the web server process on the filesystem.
Problem types
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Product status
7.0 (semver)
12.4.4 (semver)
Credits
Yassine Damiri
Noé Susset
References
damiri.fr/en/cves/CVE-2026-41465
gryfman.fr/cves/CVE-2026-41465
www.projeqtor.com
www.vulncheck.com/...or-path-traversal-via-dynamicdialog-php