Cross-site request forgery in Emlog Pro - #VU142824
Published: August 15, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose limited sensitive information.
The vulnerability exists due to cross-site request forgery in the mail test endpoint when handling crafted cross-site requests that submit attacker-controlled SMTP host and port values. A remote attacker can cause the server to initiate SMTP connections to attacker-specified hosts and ports to disclose limited sensitive information.
User interaction is required to trigger the cross-site request.