Executive brief
Emlog, an open-source website building system, contains a security flaw in its administrative upgrade process. An attacker can trick a logged-in administrator into clicking a malicious link, which triggers the server to download and execute unauthorized database commands and web files. This can lead to a complete takeover of the website, unauthorized data modification, or the installation of persistent backdoors.
Technical details
The vulnerability exists in 'admin/upgrade.php' because the upgrade interface accepts remote SQL and ZIP URLs via GET parameters without validating a CSRF token. When an authenticated administrator is induced to visit a malicious URL, the server fetches and executes the remote SQL file and extracts the ZIP file directly into the web root directory. This allows for arbitrary SQL execution and arbitrary file writes (RCE). The issue was addressed in version 2.6.8 by switching the upgrade request method to POST, implementing host validation, and requiring CSRF tokens.
Affected products
- emlog emlog < 2.6.8
Timeline
- 2026-03-27: advisory: Vendor advisory published via GitHub
- 2026-04-03: disclosed: CVE published
- 2026-04-03: patched: Fix committed in version 2.6.8