Unrestricted File Upload Vulnerability in Emlog Pro
CVE-2024-5043

4.7MEDIUM

Key Information:

Vendor
Emlog Pro
Status
Emlog Pro
Vendor
CVE Published:
17 May 2024

Badges

👾 Exploit Exists🟡 Public PoC

Summary

A significant security vulnerability exists in Emlog Pro version 2.3.4, associated with the file 'admin/setting.php'. This flaw allows for unrestricted file uploads, potentially enabling an attacker to upload malicious files remotely. The vulnerability has been publicly disclosed, highlighting the urgent need for affected users to implement security measures to mitigate risks. Users are advised to review their security settings and update to a version that addresses this issue as the potential for exploitation remains.

Affected Version(s)

Emlog Pro 2.3.4

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

CVSS V3.1

Score:
4.7
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • 🟡

    Public PoC available

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

bydsteve (VulDB User)
.