Authorization bypass through user-controlled key in Emlog Pro - #VU142826
Published: August 15, 2026
Vulnerability details
The vulnerability allows a remote user to modify other users\' note content.
The vulnerability exists due to authorization bypass through a user-controlled key in the Notes/Twitter update function when handling update requests with a user-supplied id parameter. A remote user can send a specially crafted request to modify other users\' note content.
The issue can also be triggered through cross-site request forgery when a logged-in user visits a malicious page.