CVE-2023-41618
- EPSS 0.22%
- Veröffentlicht 14.12.2023 00:15:43
- Zuletzt bearbeitet 21.11.2024 08:21:22
Emlog Pro v2.1.14 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the component /admin/article.php?active_savedraft.
CVE-2023-41621
- EPSS 9.23%
- Veröffentlicht 13.12.2023 23:15:07
- Zuletzt bearbeitet 21.11.2024 08:21:22
A Cross Site Scripting (XSS) vulnerability was discovered in Emlog Pro v2.1.14 via the component /admin/store.php.
CVE-2023-41623
- EPSS 0.88%
- Veröffentlicht 12.12.2023 09:15:07
- Zuletzt bearbeitet 21.11.2024 08:21:22
Emlog version pro2.1.14 was discovered to contain a SQL injection vulnerability via the uid parameter at /admin/media.php.
CVE-2023-44974
- EPSS 14.3%
- Veröffentlicht 03.10.2023 21:15:10
- Zuletzt bearbeitet 21.11.2024 08:26:10
An arbitrary file upload vulnerability in the component /admin/plugin.php of Emlog Pro v2.2.0 allows attackers to execute arbitrary code via uploading a crafted PHP file.
CVE-2023-44973
- EPSS 0.44%
- Veröffentlicht 03.10.2023 21:15:10
- Zuletzt bearbeitet 21.11.2024 08:26:10
An arbitrary file upload vulnerability in the component /content/templates/ of Emlog Pro v2.2.0 allows attackers to execute arbitrary code via uploading a crafted PHP file.
CVE-2023-43267
- EPSS 0.22%
- Veröffentlicht 02.10.2023 21:15:34
- Zuletzt bearbeitet 21.11.2024 08:23:54
A cross-site scripting (XSS) vulnerability in the publish article function of emlog pro v2.1.14 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the title field.
CVE-2023-43291
- EPSS 17.62%
- Veröffentlicht 27.09.2023 15:19:33
- Zuletzt bearbeitet 21.11.2024 08:23:56
Deserialization of Untrusted Data in emlog pro v.2.1.15 and earlier allows a remote attacker to execute arbitrary code via the cache.php component.
CVE-2023-39121
- EPSS 1.75%
- Veröffentlicht 03.08.2023 20:15:11
- Zuletzt bearbeitet 21.11.2024 08:14:45
emlog v2.1.9 was discovered to contain a SQL injection vulnerability via the component /admin/user.php.
CVE-2023-37049
- EPSS 0.12%
- Veröffentlicht 26.07.2023 13:15:10
- Zuletzt bearbeitet 21.11.2024 08:11:00
emlog 2.1.9 is vulnerable to Arbitrary file deletion via admin\template.php.
CVE-2020-19028
- EPSS 0.46%
- Veröffentlicht 05.06.2023 21:15:10
- Zuletzt bearbeitet 08.01.2025 20:15:23
*File Upload vulnerability found in Emlog EmlogCMS v.6.0.0 allows a remote attacker to gain access to sensitive information via the /admin/plugin.php function.