Executive brief
Emlog is an open-source website building and blogging platform. A security flaw allows an authorized user (such as a blog author) to trick the system into running malicious code by manipulating how article templates are loaded. If an attacker can upload a file to the server through any means, they can use this vulnerability to take full control of the website and its data.
Technical details
A Local File Inclusion (LFI) vulnerability exists in Emlog Pro versions 2.6.13 and earlier due to improper validation of the 'template' parameter in the article publishing interface. The 'api_controller.php' script fails to sanitize path traversal sequences (../) before storing the template path in the database. When the article is subsequently viewed, 'log_controller.php' retrieves this path and passes it to 'View::getView()', which performs a direct PHP 'include'. An authenticated attacker with author privileges can exploit this to execute arbitrary PHP code, provided they have a method to upload a malicious file elsewhere on the server. No official patch has been identified at the time of this advisory.
Affected products
- Emlog Emlog Pro <= 2.6.13
Timeline
- 2026-05-13: advisory: Initial GitHub security advisory published
- 2026-07-16: disclosed: CVE published to NVD dataset