The Logs plugin before 3.0.4 for Craft CMS allows remote attackers to read arbitrary files via input to actionStream in Controller.php.
{ "severity": "MODERATE", "github_reviewed": true, "cwe_ids": [ "CWE-22" ], "github_reviewed_at": "2022-02-08T16:08:49Z", "nvd_published_at": "2022-01-31T08:15:00Z" }