Vulnerabilities (CVE)

Filtered by vendor Abelche Subscribe
Filtered by product Cola Dnslog
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-57403 1 Abelche 1 Cola Dnslog 2026-01-09 N/A 7.5 HIGH
Cola Dnslog v1.3.2 is vulnerable to Directory Traversal. When a DNS query for a TXT record is processed, the application concatenates the requested URL (or a portion of it) directly with a base path using os.path.join. This bypass allows directory traversal or absolute path injection, leading to the potential exposure of sensitive information.