PT-2026-2311 · Emlog · Emlog
Hebing123
·
Published
2026-01-12
·
Updated
2026-01-21
·
CVE-2026-22799
CVSS v4.0
9.3
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Emlog versions prior to 2.6.1
Description
Emlog is a website building system. Versions prior to 2.6.1 expose a REST API endpoint ('/index.php?rest-api=upload') for media file uploads. This endpoint does not properly validate file types, extensions, or content, allowing authenticated attackers with a valid API key or admin session cookie to upload arbitrary files, including malicious PHP scripts. Once uploaded, these files can be executed, potentially leading to remote code execution (RCE) and full server compromise. Attackers can obtain the API key by gaining administrator access or through information disclosure vulnerabilities within the application.
Recommendations
Versions prior to 2.6.1 should be updated to version 2.6.1 or later.
Exploit
Fix
RCE
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Emlog