Executive brief
EMLOG-Pro is a blogging platform used for content management. A cross-site scripting vulnerability allows attackers to inject malicious code that can be used to upload and execute a shell, potentially gaining control of the server and accessing sensitive data.
Technical details
A stored or reflected XSS vulnerability in EMLOG-Pro 2.6.29 allows attackers to inject arbitrary JavaScript. The vulnerability enables attackers to upload a malicious shell to the affected server, leading to remote code execution. Exploitation requires network access and likely some level of user interaction (such as a victim visiting a crafted link or uploading content).
Affected products
- EMLOG EMLOG-Pro 2.6.29
Timeline
- 2026-09-21: disclosed