Cross-site request forgery in Emlog Pro - CVE-2026-42286
Published: August 15, 2026
Vulnerability details
The vulnerability allows a remote user to perform unauthorized administrative actions.
The vulnerability exists due to cross-site request forgery in admin functions when handling crafted requests from an authenticated administrator\'s browser. A remote user can trick the victim into visiting a malicious page to perform unauthorized administrative actions.
User interaction is required to visit attacker-controlled content while authenticated to the application.