Executive brief
Emlog Pro, a content management system used for blogs and websites, contains a security flaw in its template upload feature. An authorized administrator can upload a specially crafted file that bypasses folder restrictions to overwrite critical system files. This allows the attacker to take complete control of the website and execute malicious code, potentially impacting all site visitors and compromising the underlying server.
Technical details
A path traversal vulnerability exists in the Emlog Pro template management module (/admin/template.php) due to insufficient sanitization of filenames within uploaded ZIP archives. The 'emUnZip' function in /admin/template.php and the extraction logic in /include/lib/common.php fail to validate or strip directory traversal sequences (e.g., '../'). An authenticated administrator can upload a ZIP file containing files with traversal paths to overwrite existing PHP files (like header.php) outside the intended template directory. This leads to arbitrary PHP code execution (RCE) with the privileges of the web server. While the vendor has released newer versions (e.g., 2.6.15), users on version 2.6.9 or older should upgrade immediately.
Affected products
- Emlog Emlog Pro Up to and including 2.6.9
Timeline
- 2026-04-05: disclosed: Vulnerability discovered and submitted to MITRE/CNVD by researcher LING12138-sg
- 2026-05-29: advisory: CVE-2026-39276 published