Impact
This flaw is a stored cross‑site scripting vulnerability in the article publishing module of Emlog CMS. An attacker who is able to authenticate as an administrator can embed arbitrary JavaScript into the article content. When another administrator opens the article for review or preview, the script runs in that admin’s browser context. The attacker can then carry out privileged actions, most notably adding a new administrator account that bypasses normal access controls.
Affected Systems
The vulnerability exists in Emlog CMS versions up to and including 2.6.14. Only installations that expose the /admin/article.php interface and allow administrators to publish articles are affected.
Risk and Exploitability
The risk is significant because exploitation requires only an authenticated administrator session; once a user is logged in, the injected script has full browser privileges. The EPSS score of < 1% indicates a low exploitation probability, and the absence from CISA KEV suggests it has not yet been widely exploited. The CVSS score of 5.4 classifies the vulnerability as medium severity, reflecting the potential for complete administrative takeover after successful exploitation.
OpenCVE Enrichment