Emlog Pro
cpe:2.3:a:emlog_pro_project:emlog_pro:*:*:*:*:*:*:*
- 2.5.4
A Server-Side Request Forgery (SSRF) vulnerability has been identified in Emlog Pro version 2.5.4, specifically within the sort.php component. This vulnerability allows attackers to scan local and internal ports by supplying a crafted URL.
Exploitation of this vulnerability allows for Server-Side Request Forgery (SSRF), which could be used to interact with internal services or resources that are not exposed to the public.
To reproduce this vulnerability, send a request to the sort.php component with a crafted URL that targets internal or local ports. This can be done by manipulating the URL parameter to scan for open ports on the localhost or other internal services.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.