Path traversal in Emlog Pro - #VU142827

 

Path traversal in Emlog Pro - #VU142827

Published: August 15, 2026


Vulnerability identifier: #VU142827
CSH Severity: Low
CVSS v4: 7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to cause a denial of service.

The vulnerability exists due to path traversal in the template and plugin deletion functions when handling deletion requests. A remote privileged user can send a specially crafted request with traversal sequences to recursively delete arbitrary files and directories to cause a denial of service.

Exploitation can result in recursive deletion beyond the intended template or plugin directories because the delete routine does not enforce path containment checks.


Affected software

Emlog Pro

Remediation

Install security update from vendor's website.

Emlog Pro - update to 2.6.25

External References

Related Security Bulletins