Cross-site scripting in Emlog Pro - #VU125573

 

Cross-site scripting in Emlog Pro - #VU125573

Published: April 9, 2026 / Updated: April 10, 2026


Vulnerability identifier: #VU125573
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: N/A
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary script code in the administrator's browser.

The vulnerability exists due to cross-site scripting and missing request validation in link management when handling a forged request that creates a crafted link entry and later rendering the icon field. A remote attacker can submit a specially crafted request to execute arbitrary script code in the administrator's browser.

Exploitation requires an administrator to be logged in and to open the link management page after the crafted entry has been created.


Affected software

Emlog Pro

Remediation

Install security update from vendor's website.

Emlog Pro - update to 2.6.10

External References

Related Security Bulletins