Description
Ether Logs is a package that allows one to check one's logs in the Craft 3 utilities section. A vulnerability was found in versions prior to 3.0.4 that allowed authenticated admin users to access any file on the server. The vulnerability has been fixed in version 3.0.4. As a workaround, one may disable the plugin if untrustworthy sources have admin access.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-1462 | Ether Logs is a package that allows one to check one's logs in the Craft 3 utilities section. A vulnerability was found in versions prior to 3.0.4 that allowed authenticated admin users to access any file on the server. The vulnerability has been fixed in version 3.0.4. As a workaround, one may disable the plugin if untrustworthy sources have admin access. |
Github GHSA |
GHSA-fp63-499m-hq6m | Files or Directories Accessible to External Parties in ether/logs |
References
History
No history.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-03T23:33:55.553Z
Reserved: 2021-05-12T00:00:00.000Z
Link: CVE-2021-32752
No data.
Status : Modified
Published: 2021-07-09T14:15:08.070
Modified: 2024-11-21T06:07:40.290
Link: CVE-2021-32752
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA