github.com
https://github.com/emlog/emlog/issues/62 CVE-2021-3293
MEDIUMNuclei
emlog 5.3.1 Path Disclosure
Record summary
CVE-2021-3293 has a selected CVSS score of 5.3 (medium); EIP currently links 1 Nuclei template.
Description
emlog v5.3.1 has full path disclosure vulnerability in t/index.php, which allows an attacker to see the path to the webroot/file.
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryMEDIUMemlog 5.3.1 Path DisclosureCVSS 5.3
emlog v5.3.1 is susceptible to full path disclosure via t/index.php, which allows an attacker to see the path to the webroot/file.
Impact
An attacker can gain knowledge of the server's file system structure, potentially leading to further attacks.
Remediation
Apply the latest patch or upgrade to a version that fixes the vulnerability.
WeaknessesCWE-22
Authorsh1ei1
Template tagscve2021cveemlogfpdvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CPE: cpe:2.3:a:emlog:emlog:5.3.1:*:*:*:*:*:*:*
https://github.com/emlog/emlog/issues/62 https://github.com/thinkgad/Bugs/blob/main/emlog%20v5.3.1%20has%20Full%20Path%20Disclosure%20vulnerability.md https://nvd.nist.gov/vuln/detail/CVE-2021-3293 https://github.com/Z0fhack/Goby_POC https://github.com/20142995/Goby
Source: ProjectDiscovery
References
3github.com
https://github.com/thinkgad/Bugs/blob/main/emlog%20v5.3.1%20has%20Full%20Path%20Disclosure%20vulnerability.md nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-3293