Cross-Site Scripting Vulnerability in Emlog Pro Affecting Multiple Versions
CVE-2024-12846
Key Information:
Badges
What is CVE-2024-12846?
The vulnerability CVE-2024-12846 affects Emlog Pro versions up to 2.4.1, specifically targeting the /admin/link.php file. An attacker can exploit this vulnerability through a crafted request that manipulates the siteurl/icon parameter, leading to cross-site scripting (XSS) situations. As a result, this flaw can allow unauthorized users to execute scripts in the context of the affected user's session. Given its capability for remote exploitation, it poses a significant risk to sensitive data and user interactions, making timely patching essential.
Affected Version(s)
Emlog Pro 2.4.0
Emlog Pro 2.4.1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved