A vulnerability, which was classified as problematic, has been found in Emlog Pro up to 2.4.1. Affected by this issue is some unknown functionality of the file /admin/link.php. The manipulation of the argument siteurl/icon leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Metrics
Affected Vendors & Products
References
History
Sat, 21 Dec 2024 05:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability, which was classified as problematic, has been found in Emlog Pro up to 2.4.1. Affected by this issue is some unknown functionality of the file /admin/link.php. The manipulation of the argument siteurl/icon leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. | |
Title | Emlog Pro link.php cross site scripting | |
Weaknesses | CWE-79 CWE-94 |
|
References |
| |
Metrics |
cvssV2_0
|
MITRE
Status: PUBLISHED
Assigner: VulDB
Published: 2024-12-21T05:00:11.038Z
Updated: 2024-12-21T05:00:11.038Z
Reserved: 2024-12-20T12:35:57.370Z
Link: CVE-2024-12846
Vulnrichment
No data.
NVD
Status : Received
Published: 2024-12-21T05:15:07.373
Modified: 2024-12-21T05:15:07.373
Link: CVE-2024-12846
Redhat
No data.