Cross-site request forgery in Emlog Pro - CVE-2026-21430
Published: August 15, 2026
Vulnerability details
The vulnerability allows a remote user to take over an account.
The vulnerability exists due to cross-site request forgery chained with stored cross-site scripting in the Emlog Pro application when handling crafted web requests and stored script content. A remote user can submit a crafted request and inject malicious script content to take over an account.
Exploitation requires authentication and relies on chaining both issues together.