Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4r29-3qq2-w2vw

Опубликовано: 08 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

Emlog Pro 2.5.20 has an arbitrary file deletion vulnerability. This vulnerability stems from the admin/template.php component and the admin/plugin.php component. They fail to perform path verification and dangerous code filtering for deletion parameters, allowing attackers to exploit this feature for directory traversal.

Emlog Pro 2.5.20 has an arbitrary file deletion vulnerability. This vulnerability stems from the admin/template.php component and the admin/plugin.php component. They fail to perform path verification and dangerous code filtering for deletion parameters, allowing attackers to exploit this feature for directory traversal.

EPSS

Процентиль: 79%
0.0125
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-24

Связанные уязвимости

CVSS3: 9.1
nvd
2 месяца назад

Emlog Pro 2.5.20 has an arbitrary file deletion vulnerability. This vulnerability stems from the admin/template.php component and the admin/plugin.php component. They fail to perform path verification and dangerous code filtering for deletion parameters, allowing attackers to exploit this feature for directory traversal.

EPSS

Процентиль: 79%
0.0125
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-24