Cross-site scripting in Emlog Pro - #VU142823
Published: August 15, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary script in an administrator\'s browser and escalate privileges.
The vulnerability exists due to cross-site scripting in the SVG file upload and media library link handling when processing uploaded SVG files that contain malicious JavaScript. A remote user can upload a specially crafted SVG file and have an administrator open it from the media library to execute arbitrary script in an administrator\'s browser and escalate privileges.
User interaction is required for an administrator to browse or click the uploaded file in the media library.