Platform
php
Component
emlog
Fixed in
2.5.24
Emlog is an open source website building system. In version 2.5.23, article creation functionality is vulnerable to cross-site request forgery (CSRF). This can lead to a user being forced to post an article with arbitrary, attacker-controlled content. This, when combined with stored cross-site scripting, leads to account takeover. As of time of publication, no known patched versions are available.
Exploit Status
EPSS
0.03% (9% percentile)
CISA SSVC
Update to a patched version when available. Until then, carefully review and validate all user inputs to prevent XSS. Implement robust CSRF protections on all sensitive operations.
Vulnerability analysis and critical alerts directly to your inbox.
Upload your dependency file and we'll tell you instantly if this and other CVEs hit you.