PT-2026-2311 · Emlog · Emlog

Hebing123

·

Publicado

2026-01-12

·

Atualizado

2026-01-21

·

CVE-2026-22799

CVSS v4.0

9.3

Crítica

VetorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Emlog versions prior to 2.6.1
Description Emlog is a website building system. Versions prior to 2.6.1 expose a REST API endpoint ('/index.php?rest-api=upload') for media file uploads. This endpoint does not properly validate file types, extensions, or content, allowing authenticated attackers with a valid API key or admin session cookie to upload arbitrary files, including malicious PHP scripts. Once uploaded, these files can be executed, potentially leading to remote code execution (RCE) and full server compromise. Attackers can obtain the API key by gaining administrator access or through information disclosure vulnerabilities within the application.
Recommendations Versions prior to 2.6.1 should be updated to version 2.6.1 or later.

Exploit

Correção

RCE

Unrestricted File Upload

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-22799
GHSA-P837-MRW9-5X5J

Produtos afetados

Emlog