Emlog Pro
cpe:2.3:a:emlog_pro_project:emlog_pro:*:*:*:*:*:*:*
- <= 2.4.3
A cross-site scripting (XSS) vulnerability has been identified in Emlog Pro versions through 2.4.3. The issue arises in the cover image upload feature within the file '/admin/article.php?action=upload_cover'. The vulnerability allows remote attackers to upload SVG files containing malicious XML, which is not properly sanitized before being processed.
Exploitation of this vulnerability allows for stored cross-site scripting, where uploaded SVG files are injected with scripts that can execute in the context of the user viewing the article.
To reproduce this vulnerability, upload an SVG file as a cover image through the article management interface. The SVG file must contain malicious XML code, such as a script that alerts your cookies. Once uploaded, the injected script will execute when the article is viewed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.