Cross-site request forgery in Emlog Pro - #VU142825
Published: August 15, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary SQL commands.
The vulnerability exists due to missing csrf protection in the execute_tool endpoint when handling cross-site requests to the query_database tool. A remote attacker can cause a logged-in administrator\'s browser to submit a specially crafted request to execute arbitrary SQL commands.
Only instances with AI features enabled are vulnerable. User interaction is required for an administrator to visit a malicious page or click a crafted link.