Crafty Path Traversal: When Plugins Go Rogue and Logs Take a Detour!

In a classic case of “oops, did I do that?”, the Ethercreative Logs plugin for Craft CMS had a path traversal vulnerability, allowing attackers to snoop around like nosy neighbors. But worry not, version 3.0.4 swooped in like a superhero, patching things up faster than you can say “CVE-2022-23409.”

Pro Dashboard

Hot Take:

Ethercreative Logs plugin for Craft CMS had a bit of a path-traversal mishap! It’s like the plugin accidentally turned into a nosy neighbor, peeking into places it shouldn’t. But fear not, the developers have tightened the reins and sent this plugin back on the right track – version 3.0.4 is all about minding its own business now!

Key Points:

  • The Ethercreative Logs plugin had a vulnerability that allowed path traversal.
  • Attackers needed admin access to exploit the issue.
  • The vulnerability was reported in July 2021 and patched within days.
  • Version 3.0.4 or higher resolves this pesky problem.
  • Users are advised to update immediately or uninstall the plugin.

Membership Required

 You must be a member to access this content.

View Membership Levels
Already a member? Log in here
The Nimble Nerd
Confessional Booth of Our Digital Sins

Okay, deep breath, let's get this over with. In the grand act of digital self-sabotage, we've littered this site with cookies. Yep, we did that. Why? So your highness can have a 'premium' experience or whatever. These traitorous cookies hide in your browser, eagerly waiting to welcome you back like a guilty dog that's just chewed your favorite shoe. And, if that's not enough, they also tattle on which parts of our sad little corner of the web you obsess over. Feels dirty, doesn't it?