External Control of File Name or Path in Emlog Pro - #VU142828

 

External Control of File Name or Path in Emlog Pro - #VU142828

Published: August 15, 2026


Vulnerability identifier: #VU142828
CSH Severity: Medium
CVSS v4: 7.2 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-73
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to delete arbitrary files on the server.

The vulnerability exists due to external control of file name or path in the media external resource handling and media deletion functionality when processing a user-supplied file:// URI. A remote user can submit a crafted external resource and then delete the media record to delete arbitrary files on the server.

The issue affects users with Writer-role access, and exploitation can lead to site takeover if a critical file such as config.php is deleted and the installer becomes accessible again.


Affected software

Emlog Pro

Remediation

Install security update from vendor's website.

Emlog Pro - update to 2.6.25

External References

Related Security Bulletins