Cross-site scripting in Emlog Pro - #VU142823

 

Cross-site scripting in Emlog Pro - #VU142823

Published: August 15, 2026


Vulnerability identifier: #VU142823
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: N/A
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary script in an administrator\'s browser and escalate privileges.

The vulnerability exists due to cross-site scripting in the SVG file upload and media library link handling when processing uploaded SVG files that contain malicious JavaScript. A remote user can upload a specially crafted SVG file and have an administrator open it from the media library to execute arbitrary script in an administrator\'s browser and escalate privileges.

User interaction is required for an administrator to browse or click the uploaded file in the media library.


Affected software

Emlog Pro

Remediation

Install security update from vendor's website.

Emlog Pro - update to 2.6.25

External References

Related Security Bulletins