Cross-Site Scripting Vulnerability in Emlog Pro Revealed
CVE-2024-12843
What is CVE-2024-12843?
CVE-2024-12843 identifies a high-risk cross-site scripting (XSS) vulnerability within Emlog Pro versions up to 2.4.1. The flaw arises from improper handling of user input in the /admin/plugin.php file, specifically in the argument 'filter'. This oversight allows attackers to inject malicious scripts that can be executed in the context of the user’s browser, potentially leading to data theft, session hijacking, or other nefarious activities. The vulnerability is publicly disclosed and can be exploited remotely, emphasizing the urgent need for users to update their Emlog Pro installations to safeguard against potential attacks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Emlog Pro 2.4.0
Emlog Pro 2.4.1
References
CVSS V4
Timeline
Vulnerability published
