CVE-2023-39121
Emlog 2.1.9 - SQL Injection
Record summary
CVE-2023-39121 has a selected CVSS score of 7.2 (high); EIP currently links 1 Nuclei template.
Description
emlog v2.1.9 was discovered to contain a SQL injection vulnerability via the component /admin/user.php.
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 17, 2024 · Source: CVE List
Nuclei templates
1ProjectDiscoveryHIGHEmlog 2.1.9 - SQL InjectionCVSS 7.2
emlog v2.1.9 contains a SQL injection caused by unsanitized input in the data backup/restore functionality, allowing attackers to execute arbitrary SQL commands through crafted backup files.
Impact
Attackers with admin credentials can execute arbitrary SQL commands, potentially leading to privilege escalation, data leakage, modification, or deletion.
Remediation
Update to the latest version of emlog or apply security patches addressing the SQL injection vulnerability.
Source: ProjectDiscovery