Critical Vulnerability in Emlog Pro 2.3.4 Allows Unrestricted File Upload
CVE-2024-5043
4.7MEDIUM
Key Information
- Vendor
- Emlog Pro
- Status
- Emlog Pro
- Vendor
- CVE Published:
- 17 May 2024
Summary
A vulnerability was found in Emlog Pro 2.3.4 and classified as critical. Affected by this issue is some unknown functionality of the file admin/setting.php. The manipulation leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-264740. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Affected Version(s)
Emlog Pro = 2.3.4
CVSS V3.1
Score:
4.7
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Risk change from: null to: 4.7 - (MEDIUM)
VulDB entry last update
Vulnerability Reserved.
VulDB entry created
Advisory disclosed
Vulnerability published.
Collectors
NVD DatabaseMitre Database
Credit
bydsteve (VulDB User)