PT-2024-23726 · Emlog · Emlog
Jixin Zhang
+1
·
Published
2024-04-02
·
Updated
2025-06-10
·
CVE-2024-31013
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
emlog version Pro 2.3
Description
The issue allows remote attackers to execute arbitrary code via a crafted payload to the bottom of the homepage in the
footer info parameter. This is a Cross Site Scripting (XSS) issue.Recommendations
For emlog version Pro 2.3, consider restricting access to the
footer info parameter to minimize the risk of exploitation. Avoid using the footer info parameter until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.XSS
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Emlog