Page 2 of 23 results (0.027 seconds)

CVSS: 5.5EPSS: 0%CPEs: 1EXPL: 0

02 Oct 2023 — A cross-site scripting (XSS) vulnerability in the publish article function of emlog pro v2.1.14 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the title field. Una vulnerabilidad de Cross-Site Scripting (XSS) en la función de publicación de artículos de emlog pro v2.1.14 permite a los atacantes ejecutar scripts web o HTML de su elección a través de un payload manipulado inyectado en el campo del título. • https://gist.github.com/Fliggyaaa/b61c24e828cbcfac42406be408665280 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 10.0EPSS: 13%CPEs: 1EXPL: 1

26 Sep 2023 — Deserialization of Untrusted Data in emlog pro v.2.1.15 and earlier allows a remote attacker to execute arbitrary code via the cache.php component. La Deserialización de Datos No Confiables en emlog pro v.2.1.15 y anteriores permite a un atacante remoto ejecutar código arbitrario a través del componente cache.php. • https://gist.github.com/Dar1in9s/e3db6b04daacb68633a97581bbd5921b • CWE-502: Deserialization of Untrusted Data •

CVSS: 8.3EPSS: 0%CPEs: 1EXPL: 2

03 Aug 2023 — emlog v2.1.9 was discovered to contain a SQL injection vulnerability via the component /admin/user.php. • https://github.com/safe-b/CVE/issues/1 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVSS: 7.7EPSS: 0%CPEs: 1EXPL: 1

26 Jul 2023 — emlog 2.1.9 is vulnerable to Arbitrary file deletion via admin\template.php. • https://github.com/Num-Nine/CVE/issues/1 • CWE-862: Missing Authorization •

CVSS: 5.5EPSS: 0%CPEs: 1EXPL: 1

27 Apr 2023 — Multiple stored cross-site scripting (XSS) vulnerabilities in Emlog Pro v2.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Article Title or Article Summary parameters. • https://github.com/emlog/emlog/issues/229 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 6.4EPSS: 0%CPEs: 1EXPL: 0

13 Nov 2022 — A vulnerability has been found in emlog and classified as problematic. Affected by this vulnerability is an unknown functionality of the file admin/article_save.php. The manipulation of the argument tag leads to cross site scripting. The attack can be launched remotely. The name of the patch is 5bf7a79826e0ea09bcc8a21f69a0c74107761a02. • https://github.com/emlog/emlog/commit/5bf7a79826e0ea09bcc8a21f69a0c74107761a02 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CWE-707: Improper Neutralization •

CVSS: 4.8EPSS: 0%CPEs: 1EXPL: 1

03 Nov 2022 — Emlog Pro v1.7.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability at /admin/store.php. Se descubrió que Emlog Pro v1.7.1 contiene una vulnerabilidad de Cross-Site Scripting (XSS) reflejada en /admin/store.php. • https://github.com/emlog/emlog/issues/195 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 8.3EPSS: 0%CPEs: 1EXPL: 1

21 Oct 2022 — Emlog Pro 1.6.0 plugins upload suffers from a remote code execution (RCE) vulnerability. Una descarga de plugins de Emlog Pro versión 1.6.0, sufre una vulnerabilidad de ejecución de código remota (RCE) • https://github.com/wszdhf/cms_vul/blob/main/emlog_pro_1.6.0_rce.md • CWE-434: Unrestricted Upload of File with Dangerous Type •

CVSS: 5.4EPSS: 0%CPEs: 1EXPL: 0

29 Apr 2022 — A vulnerability, which was classified as problematic, was found in Emlog Pro up to 1.2.2. This affects the POST parameter handling of articles. The manipulation with the input <script>alert(1);</script> leads to cross site scripting. It is possible to initiate the attack remotely but it requires a signup and login by the attacker. The exploit has been disclosed to the public and may be used. • https://github.com/xiahao90/CVEproject/blob/main/xiahao.webray.com.cn/emlog%3C=pro-1.2.2%20Stored%20Cross-Site%20Scripting%28XSS%29.md • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 4.8EPSS: 0%CPEs: 1EXPL: 1

31 Jan 2022 — Emlog pro v1.1.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the component /admin/configure.php via the parameter footer_info. Se ha detectado que Emlog pro versión v1.1.1, contiene una vulnerabilidad de tipo cross-site scripting (XSS) almacenado en el componente /admin/configure.php por medio del parámetro footer_info • https://github.com/emlog/emlog/issues/147 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •