Record summary

CVE-2023-39121 has a selected CVSS score of 7.2 (high); EIP currently links 1 Nuclei template.

Description

emlog v2.1.9 was discovered to contain a SQL injection vulnerability via the component /admin/user.php.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 17, 2024 · Source: CVE List

Nuclei templates

1
ProjectDiscoveryHIGHEmlog 2.1.9 - SQL InjectionCVSS 7.2

emlog v2.1.9 contains a SQL injection caused by unsanitized input in the data backup/restore functionality, allowing attackers to execute arbitrary SQL commands through crafted backup files.

Impact

Attackers with admin credentials can execute arbitrary SQL commands, potentially leading to privilege escalation, data leakage, modification, or deletion.

Remediation

Update to the latest version of emlog or apply security patches addressing the SQL injection vulnerability.

WeaknessesCWE-89
Authorswjch611
Template tagscve2023cvesqliemlogauthenticated
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:emlog:emlog:2.1.9:-:*:*:*:*:*:*
Shodan: http.title:"emlog"
FOFA: title="emlog"
Google: intitle:"emlog"

Source: ProjectDiscovery

References

2