External Control of File Name or Path in Emlog Pro - #VU142828
Published: August 15, 2026
Vulnerability details
The vulnerability allows a remote user to delete arbitrary files on the server.
The vulnerability exists due to external control of file name or path in the media external resource handling and media deletion functionality when processing a user-supplied file:// URI. A remote user can submit a crafted external resource and then delete the media record to delete arbitrary files on the server.
The issue affects users with Writer-role access, and exploitation can lead to site takeover if a critical file such as config.php is deleted and the installer becomes accessible again.