SEPTEMBER 23, 2026
Live Feed
Back to database
Case File

CVE-2026-41465

MEDIUM · CVSS 6.5 EPSS 0.54%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2026-04-27 · Last synced 2026-08-04

CyberRota Analysis

This is a medium severity vulnerability with a CVSS score of 6.5. Exploitation may require the attacker to be authenticated.

CVE
CVE-2026-41465
Severity
MEDIUM
CVSS
6.5
EPSS
0.54%

Original NVD Description

ProjeQtor versions 7.0 through 12.4.3 contain a path traversal vulnerability in the log file viewer at dynamicDialog.php where the logname parameter is not validated against directory traversal sequences before constructing file paths. Authenticated attackers can inject directory traversal sequences ../ into the logname parameter to read arbitrary .log files accessible to the web server process on the filesystem.