bGl1o emlog pro
cpe:2.3:a:emlog_pro_project:emlog_pro:*:*:*:*:*:*:*
- 2.5.7
A vulnerability allowing arbitrary file upload has been identified in Emlog Pro version 2.5.7, specifically within the plugin management component. This issue arises because the application does not properly validate or filter uploaded files. Attackers can exploit this vulnerability by uploading a compressed file containing a PHP script, which is then executed on the server after the file is decompressed.
Exploitation of this vulnerability allows for arbitrary code execution on the server where Emlog Pro is installed.
The vulnerability can be reproduced by uploading a zip file containing a PHP script through the plugin management interface. After the file is uploaded, it can be accessed via the web server, and the PHP script will be executed, demonstrating successful exploitation.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.