Cross-Site Scripting Vulnerability in Emlog Pro Affects Remote Operations
CVE-2024-12844
What is CVE-2024-12844?
A significant cross-site scripting (XSS) vulnerability has been identified in Emlog Pro versions up to 2.4.1, specifically within the '/admin/store.php' file. This vulnerability enables attackers to manipulate the 'tag' argument, allowing for the execution of malicious scripts in the context of the affected web application. As this vulnerability can be exploited remotely, it poses a risk of unauthorized actions being executed by users, potentially leading to data theft or further compromise of the web application. Given its public disclosure, it is crucial for users and administrators of Emlog Pro to take immediate action to address this vulnerability and safeguard their systems.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Emlog Pro 2.4.0
Emlog Pro 2.4.1
References
CVSS V4
Timeline
Vulnerability published
